Fallos del tipo CWE-732

792 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2026-55441HIGHmise: Arbitrary command execution via task-include files in an untrusted, config-less repositoryEPSS 0.2%CVE-2023-1516HIGHRoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a localEPSS 0.2%CVE-2020-5385MEDIUMDell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability bEPSS 0.2%CVE-2024-22029HIGHtomcat packaging allows for escalation to root from tomcat userEPSS 0.2%CVE-2023-28399HIGHIncorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control ListEPSS 0.2%CVE-2025-27446HIGHApache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privilegesEPSS 0.2%CVE-2026-41366MEDIUMOpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-WhitelistingEPSS 0.2%CVE-2023-27084MEDIUMPermissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentCEPSS 0.2%CVE-2026-95667MEDIUMMISP Installer Log and FIFO Created World-Readable, Exposing Sensitive CredentialsEPSS 0.2%CVE-2024-54159MEDIUMstalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.EPSS 0.2%CVE-2022-41771MEDIUMIncorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticatEPSS 0.2%CVE-2024-38646HIGHNotes Station 3EPSS 0.2%CVE-2026-12957HIGHArbitrary Code Execution in Language Servers for AWSEPSS 0.2%CVE-2025-26168HIGHIXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuratiEPSS 0.2%CVE-2022-42972HIGHA CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a locEPSS 0.2%CVE-2026-7431MEDIUMAn incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user toEPSS 0.2%CVE-2026-64613MEDIUMData::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOWEPSS 0.2%CVE-2024-28745LOWImproper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing another app installed onEPSS 0.2%CVE-2022-44725HIGHOPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal uEPSS 0.2%CVE-2026-32810MEDIUMHalloy has insecure file permissions on credential filesEPSS 0.2%