Falhas do tipo CWE-732

791 resultados

Permissões Inadequadas em Recurso Crítico de Segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso viola o princípio do menor privilégio e expõe informações confidenciais ou permite alterações não intencionadas em arquivos críticos.

Exemplo

Um serviço web armazena chaves privadas de criptografia em um arquivo com permissões 644 (legível por qualquer usuário do sistema), permitindo que outro processo comprometido ou usuário local roube as credenciais. Ou um arquivo de configuração com senhas é gravado com permissões 777, permitindo modificação por qualquer usuário.

Como mitigar

Implemente permissões restritivas desde o início (ex: 600 para chaves privadas, 640 para configs sensíveis). Realize auditorias regulares de permissões em recursos críticos e use listas de controle de acesso (ACLs) para ser explícito sobre quem pode ler ou modificar cada recurso. Automatize verificações de permissões na pipeline CI/CD.

CVE-2022-3258LOWIncorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.EPSS 0.3%CVE-2025-12148MEDIUMUnauthorized access to fields protected by Field Masking (FM) for fields of type IPEPSS 0.3%CVE-2025-12147MEDIUMUnauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an objectEPSS 0.3%CVE-2020-36916HIGHTDM Digital Signage PC Player 4.1.0.4 Privilege Escalation via Insecure PermissionsEPSS 0.3%CVE-2024-44575LOWRELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to EPSS 0.3%CVE-2026-87988CRITICALAn arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unEPSS 0.3%CVE-2024-8540HIGHInsecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive aEPSS 0.3%CVE-2023-40516HIGHLG Simple Editor Incorrect Permission Assignment Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2022-44263HIGHDentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.EPSS 0.3%CVE-2023-32303MEDIUMPlanet's secret file is created with excessive permissionsEPSS 0.3%CVE-2025-48747MEDIUMNetwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission AssiEPSS 0.3%CVE-2020-26194HIGHDell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This maEPSS 0.3%CVE-2022-23448A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versionsEPSS 0.2%CVE-2026-76399HIGHIncorrect Permission Assignment for Scheduled Searches in Splunk AI ToolkitEPSS 0.2%CVE-2026-40462HIGHiControl REST and tmsh vulnerabilityEPSS 0.2%CVE-2026-76388HIGHPrivilege Escalation through Search Macro Permissions in Splunk Enterprise SecurityEPSS 0.2%CVE-2025-34189MEDIUMVasion Print (formerly PrinterLogic) Insecure Inter-Process Communication Allows Local Session HijackingEPSS 0.2%CVE-2026-34352HIGHIn TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an applicationEPSS 0.2%CVE-2021-3747HIGHMacOS version of Multipass incorrect owner for application directoryEPSS 0.2%CVE-2026-32704MEDIUMSiYuan renderSprig: missing admin check allows any user to read full workspace DBEPSS 0.2%