Weaknesses of type CWE-732

791 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2025-4609CRITICALIncorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attackerEPSS 0.4%CVE-2026-4757HIGHA VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flEPSS 0.4%CVE-2022-43915MEDIUMIBM App Connect Enterprise Certified ContainerEPSS 0.4%CVE-2025-41712MEDIUMIncorrect Permission Assignment on power analyzerEPSS 0.4%CVE-2023-30606MEDIUMMultisite denial of service through unsanitized dynamic dispatch to SiteSetting in DiscourseEPSS 0.4%CVE-2025-3936MEDIUMIncorrect Permission Assignment for Critical ResourceEPSS 0.4%CVE-2024-11497HIGHPhoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationEPSS 0.4%CVE-2023-4777LOWIncorrect Permission Assignment on Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier EPSS 0.4%CVE-2026-76104MEDIUMDell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A hiEPSS 0.4%CVE-2020-10140HIGHAcronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed fEPSS 0.4%CVE-2025-6297HIGHdpkg-deb: Fix cleanup for control member with restricted directoriesEPSS 0.4%CVE-2020-16202WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code exeEPSS 0.4%CVE-2023-1692HIGHThe window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.4%CVE-2017-12167MEDIUMIt was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user tEPSS 0.4%CVE-2023-35870MEDIUMImproper Access Control in SAP S/4HANA (Manage Journal Entry Template)EPSS 0.4%CVE-2025-0064HIGHImproper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)EPSS 0.4%CVE-2016-2121MEDIUMA permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitiveEPSS 0.4%CVE-2020-36770HIGHpkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root fEPSS 0.4%CVE-2025-43808MEDIUMThe Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10,EPSS 0.4%CVE-2026-58424HIGHPermanent Fork PR Workflow Approval Gate BypassEPSS 0.4%