CVE-2026-9651
Received
Received - Intake
Incorrect Permission Assignment in System Files Leads to Password Hash Disclosure
Publication date: 2026-06-25
Last updated on: 2026-06-25
Assigner: Schneider Electric SE
Description
Description
CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |