Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service accounts token.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.