CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,721 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 17 of 35
- CVE-2022-46761HIGHCVSS 7.5EG 7.52023-01-06
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
- CVE-2022-44561HIGHCVSS 7.5EG 7.52022-11-09
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
- CVE-2022-44557HIGHCVSS 7.5EG 7.52022-11-09
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-44554HIGHCVSS 7.5EG 7.52022-11-09
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
- CVE-2022-43574HIGHCVSS 7.5EG 7.52022-11-03
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."
- CVE-2022-32743HIGHCVSS 7.5EG 7.52022-09-01
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
- CVE-2022-37006HIGHCVSS 7.5EG 7.52022-08-10
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
- CVE-2022-33023HIGHCVSS 7.5EG 7.52022-06-29
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
- CVE-2022-23802HIGHCVSS 7.5EG 7.52022-05-06
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Informati…
- CVE-2022-29585HIGHCVSS 7.5EG 7.52022-04-28
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the inst…
- CVE-2022-29547HIGHCVSS 7.5EG 7.52022-04-21
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.
- CVE-2022-27650HIGHCVSS 7.5EG 7.52022-04-04
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process cap…
- CVE-2022-27649HIGHCVSS 7.5EG 7.52022-04-04
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process…
- CVE-2021-40049HIGHCVSS 7.5EG 7.52022-03-10
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
- CVE-2021-41652HIGHCVSS 7.5EG 7.52022-03-01
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
- CVE-2021-46086HIGHCVSS 7.5EG 7.52022-01-25
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker ca…
- CVE-2021-40004HIGHCVSS 7.5EG 7.52022-01-10
The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-39967HIGHCVSS 7.5EG 7.52022-01-03
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-44858HIGHCVSS 7.5EG 7.52021-12-20
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has a…
- CVE-2021-37030HIGHCVSS 7.5EG 7.52021-11-23
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- CVE-2021-22368HIGHCVSS 7.5EG 7.52021-06-30
There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.
- CVE-2021-22371HIGHCVSS 7.5EG 7.52021-06-30
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-21737HIGHCVSS 7.5EG 7.52021-06-24
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system custo…
- CVE-2021-33506HIGHCVSS 7.5EG 7.52021-05-26
jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation.
- CVE-2021-33038HIGHCVSS 7.5EG 7.52021-05-26
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive i…
- CVE-2021-21732HIGHCVSS 7.5EG 7.52021-05-19
A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper permission settings, third-party applications can read some files in the proc file system without authorization. Attackers could exploit this vulne…
- CVE-2020-21342HIGHCVSS 7.5EG 7.52021-05-13
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
- CVE-2020-27569HIGHCVSS 7.5EG 7.52021-04-21
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
- CVE-2020-27568HIGHCVSS 7.5EG 7.52021-04-21
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.
- CVE-2020-27665HIGHCVSS 7.5EG 7.52020-10-22
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
- CVE-2020-23971HIGHCVSS 7.5EG 7.52020-09-01
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads whi…
- CVE-2020-24584HIGHCVSS 7.5EG 7.52020-09-01
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
- CVE-2020-24583HIGHCVSS 7.5EG 7.52020-09-01
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of upl…
- CVE-2020-2077HIGHCVSS 7.5EG 7.52020-07-29
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST…
- CVE-2019-9943HIGHCVSS 7.5EG 7.52020-06-17
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because grou…
- CVE-2020-12695HIGHCVSS 7.5EG 7.52020-06-08
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the Call…
- CVE-2020-13894HIGHCVSS 7.5EG 7.52020-06-07
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
- CVE-2017-18669HIGHCVSS 7.5EG 7.52020-04-07
An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017).
- CVE-2017-18668HIGHCVSS 7.5EG 7.52020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017).
- CVE-2019-3944HIGHCVSS 7.5EG 7.52020-04-01
Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
- CVE-2020-10792HIGHCVSS 7.5EG 7.52020-03-20
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
- CVE-2020-7943HIGHCVSS 7.5EG 7.52020-03-11
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which …
- CVE-2020-7972HIGHCVSS 7.5EG 7.52020-02-05
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
- CVE-2019-19724HIGHCVSS 7.5EG 7.52019-12-18
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud…
- CVE-2010-5108HIGHCVSS 7.5EG 7.52019-11-13
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
- CVE-2012-5577HIGHCVSS 7.5EG 7.52019-10-28
Python keyring lib before 0.10 created keyring files with world-readable permissions.
- CVE-2019-16919HIGHCVSS 7.5EG 7.52019-10-18
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access…
- CVE-2019-16106HIGHCVSS 7.5EG 7.52019-09-10
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
- CVE-2019-9630HIGHCVSS 7.5EG 7.52019-07-08
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
- CVE-2018-8848HIGHCVSS 7.5EG 7.52018-09-26
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →