Common Weakness Enumeration

    CWE Definition / CWE-732

    CWE-732: Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

    Published:8 Sep 2008
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-285: Improper Authorization

    CWE-668: Exposure of Resource to Wrong Sphere