VulnSea

CWE-732

CVEs classified under CWE-732, newest first.

70 CVEsRSS

CVE-2026-13673High· 8.8
3d ago

An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write…

An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write…

TwilightSynology · DiskStation Manager (DSM)EPSS 0.31%via NVD
CVE-2026-85887High· 7.7
3d ago

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft 365 CopilotEPSS 0.48%via NVD
CVE-2026-45726High· 7.6
4d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle…

Twilightsiderolabs · omniEPSS 0.10%via NVD
CVE-2026-92941Critical· 10.0PoC
4d ago

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls an…

Abyssalpatriksimek · vm2EPSS 0.27%via NVD
CVE-2026-76104Medium· 5.5
5d ago

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading t…

Sunlitdell · objectscaleEPSS 0.38%via NVD
CVE-2026-76159High· 7.0
6d ago

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attack…

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attack…

TwilightDuplicati · DuplicatiEPSS 0.10%via NVD
CVE-2026-48722Medium· 5.5
6d ago

Nextflow is a DSL for data-driven computational pipelines

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.…

Sunlitnextflow-io · nextflowEPSS 0.10%via NVD
CVE-2026-65348Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected par…

Sunlitapple · ipadosEPSS 0.12%via NVD
CVE-2024-58383High· 7.3PoC
1w ago

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…

Midnightfroxlor · froxlorEPSS 0.10%via NVD
CVE-2026-54447High· 8.4
1w ago

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token directory and garmin_tokens.json without explicit ow…

Twilightcyberjunky · python-garminconnectEPSS 0.10%via NVD
CVE-2026-57843Medium· 5.5
1w ago

NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, whi…

NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, whi…

SunlitThe NetBSD Foundation · NetBSDEPSS 0.10%via NVD
CVE-2026-87988Critical· 10.0
1w ago

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside…

Midnightmistralai · mistral-vibeEPSS 0.25%via NVD
CVE-2026-19583Critical· 9.9
1w ago

Velociraptor Required Permissions bypass by using client monitoring queries

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…

MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG
CVE-2026-84828Medium· 6.5
1w ago

A flaw was found in PCS (Pacemaker Configuration System)

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the fi…

SunlitRed Hat · pcsEPSS 0.10%via NVD
CVE-2026-79617High· 7.1PoC
1w ago

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

MidnightTÜBİTAK BİLGEM Software Technologies Research Institute · Pardus LightDM GreeterEPSS 0.14%via NVD
CVE-2026-80054Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access c…

Sunlitdell · secure_connect_gatewayEPSS 0.13%via NVD
CVE-2026-82312Low· 1.8⚖ disputed
2w ago

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

SunlitOpenVPN · OpenVPNEPSS 0.10%via NVD
CVE-2026-80112High· 7.8
2w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged loca…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged loca…

TwilightEPSS 0.10%via NVD
CVE-2026-79783Low· 3.6
3w ago

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservati…

Sunlitrclone · github.com/rclone/rcloneEPSS 0.14%via NVD
GHSA-m5w8-4gq2-6f8xCritical· 10.0
1mo ago

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

Midnightvm2 · vm2via GHSA
CVE-2026-73664None
1mo ago

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the ast…

SunlitEPSS 0.65%via NVD
CVE-2026-50544Medium· 6.3
1mo ago

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\…

SunlitNortheBridge · luminalshineEPSS 0.09%via NVD
CVE-2026-14478High· 7.8
1mo ago

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact conf…

Twilightautodesk · installerEPSS 0.11%via NVD
CVE-2026-65940Medium· 6.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

SunlitEPSS 0.21%via NVD
CVE-2026-63522High· 7.8
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Azure SQL DatabaseEPSS 0.24%via CVEORG
CVE-2026-48790Medium· 5.5
1mo ago

Turso CLI is the command line interface (CLI) to the open-source database Turso

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credenti…

Sunlittursodatabase · github.com/tursodatabase/turso-cliEPSS 0.10%via NVD
GHSA-945v-v9p3-v5xwLow· 3.6
1mo ago

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-50570High· 8.5
1mo ago

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Twilightfission · github.com/fission/fissionEPSS 0.27%via GHSA
CVE-2026-13769Medium· 5.5
1mo ago

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

Sunlitawscli · awscliEPSS 0.16%via OSV
CVE-2026-60659High· 7.1
2mo ago

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems)

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure wh…

Twilightoracle · solarisEPSS 0.13%via NVD
CWE-732 vulnerabilities (CVEs) · VulnSea