incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.