Threats Tagged 'cwe-732'
View all threats tagged with 'cwe-732'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-732'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-89281 is a vulnerability in the Apache Lounge Windows distribution of Apache HTTP Server. It involves a hardcoded configuration path in the openssl.cnf file that leads to incorrect permission assignment for a critical resource. This flaw can allow local code execution on affected systems. Join the discussion | CVE Database V5 | 09/22/2026, 19:17:19 UTC Added: 09/22/2026, 19:33:30 UTC |
0 The Apache Lounge Windows distribution of Apache HTTP Server contains a vulnerability due to insecure default installation directory permissions on the C:\ drive. The default install directory grants write access to Authenticated Users, which is an incorrect permission assignment for a critical resource. Join the discussion | CVE Database V5 | 09/22/2026, 19:17:15 UTC Added: 09/22/2026, 19:33:30 UTC |
0 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under common or permissive configurations, other local users can read the backup and retain Atlassian access through the refresh token. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens_to_file, refresh_token, access_token, and umask, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 09/22/2026, 18:48:58 UTC Added: 09/22/2026, 19:03:36 UTC |
0 CVE-2026-77268 is a medium severity vulnerability in sooperset's mcp-atlassian server prior to version 0.22.0. The issue involves incorrect permission assignment for critical OAuth token files, allowing local users or processes with group or world access to read access and refresh tokens, potentially enabling session reuse. The vulnerability is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 09/22/2026, 18:44:46 UTC Added: 09/22/2026, 19:03:36 UTC |
0 Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. Join the discussion | CVE Database V5 | 09/21/2026, 19:38:20 UTC Added: 09/21/2026, 19:47:18 UTC |
0 Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. Join the discussion | GCVE Database | 09/17/2026, 23:04:48 UTC Added: 09/18/2026, 01:01:03 UTC |
0 Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceService if the importing actor has not rotated those secrets, exposing Kubernetes, Talos, and etcd CA private keys plus the service-account key. The Kubernetes CA private key permits certificate signing for privileged identities such as system:masters and provides control of the imported cluster outside Omni's authorization boundary, including its workloads, credentials, and secrets. This issue is fixed in versions 1.6.6 and 1.7.3. Join the discussion | CVE Database V5 | 09/17/2026, 19:37:50 UTC Added: 09/17/2026, 19:47:20 UTC |
0 Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. Join the discussion | CVE Database V5 | 09/16/2026, 15:13:55 UTC Added: 09/16/2026, 15:32:24 UTC |
0 Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy without setting restrictive file permissions, allowing the default umask 022 to create the file with mode 0644. On a multi-user POSIX host, a local user who can traverse the victim's home directory can read seqera-auth.config and impersonate the victim against Seqera Platform within the token's scope. Single-user systems and headless CI runners that do not use the interactive login flow are not affected. This issue is fixed in 25.10.6 and 26.04.3. Join the discussion | GCVE Database | 09/15/2026, 14:07:45 UTC Added: 06/26/2026, 22:06:31 UTC |
0 garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token directory and garmin_tokens.json without explicit owner-only modes, so a permissive umask such as 022 can leave the directory mode at 0755 and the token file mode at 0644. garmin_tokens.json contains di_refresh_token, and another unprivileged user on a shared Linux or macOS host can read the token and obtain persistent access to the victim's Garmin Connect account, including health, fitness, activity, and device data. The Garmin.login tokenstore path is affected, and a pre-existing loosely permissioned token file remains exposed until rewritten or manually restricted. This issue is fixed in version 0.3.5. Join the discussion | GCVE Database | 09/14/2026, 19:53:38 UTC Added: 07/16/2026, 10:40:17 UTC |
Showing 1 to 10 of 237 results