CWE-732
CVEs classified under CWE-732, newest first.
71 CVEsRSS
CVE-2026-60659High· 7.1Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems)
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure wh…
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-58424High· 8.9PoCGitea: Permanent Fork PR Workflow Approval Gate Bypass
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-59946Medium· 6.1Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVE-2026-59148High· 8.8PoCMockoon provides way to design and run mock APIs
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runti…
CVE-2026-35341High· 7.1mkfifo: permissions of an existing file are changed after FIFO creation fails
mkfifo: permissions of an existing file are changed after FIFO creation fails
CVE-2026-35361Low· 3.4mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
CVE-2026-35353Low· 3.3mkdir: -m exposes directory with umask perms before chmod (race window)
mkdir: -m exposes directory with umask perms before chmod (race window)
CVE-2026-53486Critical· 9.1Decompress: Archive extraction can create files and links outside of the target directory
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2026-44268Medium· 4.4Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect per…
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect per…
CVE-2026-50267Medium· 4.7Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
GHSA-p2fh-f5fc-44hrMedium· 6.5OpenClaw: memory-wiki ingest could read local files with operator.write scope
OpenClaw: memory-wiki ingest could read local files with operator.write scope
GHSA-55f6-4pr5-c7m5HighKahi has privilege-drop and socket/log permission issues
Kahi has privilege-drop and socket/log permission issues
CVE-2026-49340High· 8.1gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
CVE-2026-55441High· 8.6Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
CVE-2026-32315Medium· 5.5motionEye's World-Readable Configuration File Exposes Admin Password Hash
motionEye's World-Readable Configuration File Exposes Admin Password Hash
CVE-2026-54327Low· 2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
GHSA-vqj9-vhg4-27mgMedium· 5.5Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
CVE-2026-0271High· 7.8A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iO…
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iO…
CVE-2026-10840High· 7.1A flaw was found in the OpenShift Pipelines operator
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role Cluster…
CVE-2026-8070High· 7.3Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update …
Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update …
CVE-2026-41217High· 7.9A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Applianc…
CVE-2026-8069High· 7.8PoCPredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigu…
CVE-2026-6842Low· 2.5A flaw was found in nano
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.…
CVE-2026-21727Low· 3.3A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user wi…
CVE-2025-41118Critical· 9.1Pyroscope is an open-source continuous profiling database
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacke…
CVE-2026-21715Low· 3.3A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under…
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under…
CVE-2025-12801Medium· 6.5A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows th…
CVE-2026-0775High· 7.00daynpm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute…
CVE-2026-24049High· 7.1PoCwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after e…