VariantDraft
CWE-279Incorrect Execution-Assigned Permissions
Category: authz
Description
While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.
Common consequences· 1
- Confidentiality / Integrity — Read Application Data, Modify Application Data
Potential mitigations· 2
- [Architecture and Design, Operation]Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- [Architecture and Design]
Related CAPEC attack patterns· 1
References
Exploits (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Web Server Logs Tamperingcapec-81 | 100% | live |
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-14025cve-2025-14025 | 0% | live |
| Vulnerability | CVE-2025-58437cve-2025-58437 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.