Weaknesses of type CWE-732

792 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2022-3258LOWIncorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.EPSS 0.3%CVE-2020-36916HIGHTDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure PermissionsEPSS 0.3%CVE-2025-12147MEDIUMUnauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an objectEPSS 0.3%CVE-2025-12148MEDIUMUnauthorized access to fields protected by Field Masking (FM) for fields of type IPEPSS 0.3%CVE-2024-44575LOWRELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to EPSS 0.3%CVE-2026-87988CRITICALAn arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unEPSS 0.3%CVE-2023-40516HIGHLG Simple Editor Incorrect Permission Assignment Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2024-8540HIGHInsecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive aEPSS 0.3%CVE-2023-32303MEDIUMPlanet's secret file is created with excessive permissionsEPSS 0.3%CVE-2022-44263HIGHDentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.EPSS 0.3%CVE-2025-48747MEDIUMNetwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission AssiEPSS 0.3%CVE-2020-26194HIGHDell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This maEPSS 0.3%CVE-2022-23448—A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versionsEPSS 0.2%CVE-2026-40462HIGHiControl REST and tmsh vulnerabilityEPSS 0.2%CVE-2026-76399HIGHIncorrect Permission Assignment for Scheduled Searches in Splunk AI ToolkitEPSS 0.2%CVE-2026-76388HIGHPrivilege Escalation through Search Macro Permissions in Splunk Enterprise SecurityEPSS 0.2%CVE-2026-34352HIGHIn TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an applicationEPSS 0.2%CVE-2025-34189MEDIUMVasion Print (formerly PrinterLogic) Insecure Inter-Process Communication Allows Local Session HijackingEPSS 0.2%CVE-2021-3747HIGHMacOS version of Multipass incorrect owner for application directoryEPSS 0.2%CVE-2026-32704MEDIUMSiYuan renderSprig: missing admin check allows any user to read full workspace DBEPSS 0.2%