CWE-732Class1 in KEV

Incorrect Permission Assignment for Critical Resource

Draft in the CWE catalog · 593 CVEs mapped

593
CVEs mapped
1
In KEV
7.1
Median CVSS
What it is

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Recent examples
5.5cvss
CVE-2026-80054

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for…

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

MEDIUMno explanation yet
epss
1.8cvss
CVE-2026-82312

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC…

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

LOWno explanation yet
epss
7.8cvss
CVE-2026-80112

CVE-2026-80112 - HIGH Severity Vulnerability

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-732
Abstraction
Class
Structure
Simple
Status
Draft
References (6)