CWE-689: Permission Race Condition During Resource Copy

low-risk

The product, while copying or cloning a resource, does not set the resource's permissions or access control until the copy is complete, leaving the resource exposed to other spheres while the copy is taking place.

Abstraction: Compound

Common Consequences

Confidentiality Read Application Data

Real-World Examples (3)

CVE CVSS EPSS KEV
CVE-2025-40909 5.9 0.0%
CVE-2022-28768 8.8 0.0%
CVE-2025-0087 5.1 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal