CWE-279: Incorrect Execution-Assigned Permissions
While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.
23 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-22843 — Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
- CVE-2025-14025 — Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-23263 — NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es
- CVE-2026-20062 — A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode
- CVE-2025-13663 — Quartus Prime Pro Edition Installer Advisory
- CVE-2024-37025 — Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer bef
- CVE-2025-20612 — Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
- CVE-2025-12801 — Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
- CVE-2025-23233 — Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
- CVE-2026-4948 — Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
- CVE-2025-36228 — Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2024-39286 — Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver bef
- CVE-2025-30001 — Apache StreamPark: Authenticated users can trigger remote command execution
Recently published
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4948 — Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
- CVE-2026-20062 — A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode
- CVE-2025-12801 — Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
- CVE-2025-14025 — Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
- CVE-2025-36228 — Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
- CVE-2025-13663 — Quartus Prime Pro Edition Installer Advisory
- CVE-2025-30001 — Apache StreamPark: Authenticated users can trigger remote command execution
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-23263 — NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es
- CVE-2025-23233 — Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
- CVE-2025-22843 — Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
- CVE-2025-20612 — Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow
- CVE-2024-39286 — Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver bef
- CVE-2024-37025 — Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer bef