CWE-732 关键资源的不正确权限授予 类弱点 475 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-732属于权限配置错误漏洞,指关键资源被赋予过于宽泛的访问权限,导致非预期主体可读取或修改。攻击者常利用此缺陷窃取敏感数据或篡改系统配置,引发信息泄露或服务中断。开发者应避免使用默认宽松权限,严格遵循最小权限原则,在代码中显式设置精确的访问控制列表,并定期审计资源权限配置,确保仅授权必要主体访问。
#define OUTFILE "hello.out" umask(0); FILE *out; /* Ignore link following (CWE-59) for brevity */ out = fopen(OUTFILE, "w"); if (out) { fprintf(out, "hello world!\n"); fclose(out); }-rw-rw-rw- 1 username 13 Nov 24 17:58 hello.outfunction createUserDir($username){ $path = '/home/'.$username; if(!mkdir($path)){ return false; } if(!chown($path,$username)){ rmdir($path); return false; } return true; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-53856 | OpenClaw 2026.4.24前配置文件恢复权限漏洞 — OpenClaw | 5.5 | Medium | 2026-06-16 |
| CVE-2026-0271 | Palo Alto Networks Prisma Access Agent 安全漏洞 — Prisma Access Agent | - | - | 2026-06-10 |
| CVE-2026-26422 | Clash Verge Rev 安全漏洞 — clash-verge-service-ipc | 8.4 | High | 2026-06-06 |
| CVE-2026-50590 | Mimecast Incydr 安全漏洞 — Incydr | 4.5 | Medium | 2026-06-05 |
| CVE-2026-10840 | Red Hat OpenShift Pipelines 安全漏洞 — Builds for Red Hat OpenShift | 7.1 | High | 2026-06-04 |
| CVE-2026-50209 | Acer M6E 安全漏洞 — Connect M6E 5G Portable WiFi Router | - | - | 2026-06-04 |
| CVE-2021-4481 | Dräger Protector Software 安全漏洞 — Protector Software | 8.2 | High | 2026-06-02 |
| CVE-2021-4480 | Dräger Protector Software 安全漏洞 — Protector Software | 8.2 | High | 2026-06-02 |
| CVE-2026-10591 | Amazon Kiro IDE 安全漏洞 — Kiro IDE | 8.8 | High | 2026-06-02 |
| CVE-2026-27788 | Fsas ServerView Agents 安全漏洞 — ServerView Agents for Windows | - | - | 2026-06-01 |
| CVE-2026-9508 | Suprema BioStar 安全漏洞 — BioStar 2 (server) | - | - | 2026-05-29 |
| CVE-2026-7480 | ASUS System Control Interface 安全漏洞 — ASUS System Control Interface | - | - | 2026-05-29 |
| CVE-2026-8070 | ASUS Armoury Crate 安全漏洞 — Armoury Crate | - | - | 2026-05-29 |
| CVE-2026-2254 | Hitachi Vantara Pentaho Data Integration and Analytics 安全漏洞 — Pentaho Data Integration and Analytics | 6.3 | Medium | 2026-05-27 |
| CVE-2026-25112 | Genetec RabbitMQ 安全漏洞 — Genetec RabbitMQ | 7.8 | High | 2026-05-26 |
| CVE-2026-45246 | Summarize 安全漏洞 — summarize | 5.5 | Medium | 2026-05-18 |
| CVE-2026-8612 | WWW::Mechanize::Cached 代码问题漏洞 — WWW::Mechanize::Cached | - | - | 2026-05-15 |
| CVE-2026-41959 | F5 BIG-IP和F5 BIG-IQ 安全漏洞 — BIG-IP | 6.5 | Medium | 2026-05-13 |
| CVE-2026-42058 | F5 BIG-IP 安全漏洞 — BIG-IP | 4.3 | Medium | 2026-05-13 |
| CVE-2026-42937 | F5 BIG-IP和F5 BIG-IQ 安全漏洞 — BIG-IP | 5.5 | Medium | 2026-05-13 |
| CVE-2026-41217 | F5 BIG-IP 安全漏洞 — BIG-IP | 7.9 | High | 2026-05-13 |
| CVE-2026-40462 | F5 BIG-IP 安全漏洞 — BIG-IP | 6.5 | Medium | 2026-05-13 |
| CVE-2026-8110 | Ivanti Endpoint Manager 安全漏洞 — Endpoint Manager | 7.8 | High | 2026-05-12 |
| CVE-2026-7431 | Ivanti Secure Access Client 安全漏洞 — Secure Access Client | 4.4 | Medium | 2026-05-12 |
| CVE-2026-1185 | AXIS OS 安全漏洞 — AXIS OS | 5.4 | Medium | 2026-05-12 |
| CVE-2026-0541 | AXIS OS 安全漏洞 — AXIS OS | 6.7 | Medium | 2026-05-12 |
| CVE-2026-41489 | Pi-hole 安全漏洞 — pi-hole | 8.8 | High | 2026-05-11 |
| CVE-2026-45222 | Summarize 安全漏洞 — summarize | 6.1 | Medium | 2026-05-11 |
| CVE-2026-41288 | WatchGuard Agent 安全漏洞 — WatchGuard Agent | 7.8AI | HighAI | 2026-05-06 |
| CVE-2026-41686 | Claude SDK for TypeScript 安全漏洞 — anthropic-sdk-typescript | 5.5 | - | 2026-05-04 |
CWE-732(关键资源的不正确权限授予) 是常见的弱点类别,本平台收录该类弱点关联的 475 条 CVE 漏洞。