CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,721 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 18 of 35
- CVE-2017-4975HIGHCVSS 7.5EG 7.52017-06-13
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.
- CVE-2022-1109HIGHCVSS 5.5EG 7.52023-01-20
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
- CVE-2025-43442HIGHCVSS 3.3EG 7.52025-11-04
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to identify what other apps a user has installed.
- CVE-2024-23253HIGHCVSS 3.3EG 7.52024-03-08
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.
- CVE-2025-43350HIGHCVSS 2.4EG 7.52025-11-04
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.
- CVE-2024-6238HIGHCVSS 7.4EG 7.42024-06-25
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.
- CVE-2024-27171HIGHCVSS 7.4EG 7.42024-06-14
A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27167HIGHCVSS 7.4EG 7.42024-06-14
Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the refe…
- CVE-2024-27166HIGHCVSS 7.4EG 7.42024-06-14
Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27153HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27152HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27151HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affe…
- CVE-2024-27150HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27149HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27148HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27264HIGHCVSS 7.4EG 7.42024-05-22
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-For…
- CVE-2023-29131HIGHCVSS 7.4EG 7.42023-07-11
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
- CVE-2023-33291HIGHCVSS 7.4EG 7.42023-05-28
In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation. (It cannot be exploited with e-mail addresses or phon…
- CVE-2018-6683HIGHCVSS 7.4EG 7.42018-07-23
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy fil…
- CVE-2026-59119HIGHCVSS 7.3EG 7.32026-08-11
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
- CVE-2026-4793HIGHCVSS 7.3EG 7.32026-08-03
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
- CVE-2026-16247HIGHCVSS 7.3EG 7.32026-07-20
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control ins…
- CVE-2026-16246HIGHCVSS 7.3EG 7.32026-07-20
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. …
- CVE-2025-7024HIGHCVSS 7.3EG 7.32026-04-03
Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a cr…
- CVE-2025-64724HIGHCVSS 7.3EG 7.32025-12-18
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files …
- CVE-2025-8485HIGHCVSS 7.3EG 7.32025-11-12
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.
- CVE-2025-11567HIGHCVSS 7.3EG 7.32025-11-12
CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.
- CVE-2025-5199HIGHCVSS 7.3EG 7.32025-07-12
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system sta…
- CVE-2025-49144HIGHCVSS 7.3EG 7.32025-06-23
Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insec…
- CVE-2025-46355HIGHCVSS 7.3EG 7.32025-06-03
Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.
- CVE-2024-13948HIGHCVSS 7.3EG 7.32025-05-22
Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- CVE-2023-31359HIGHCVSS 7.3EG 7.32025-05-13
Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2023-31358HIGHCVSS 7.3EG 7.32025-05-13
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2024-36339HIGHCVSS 7.3EG 7.32025-05-13
A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2024-21960HIGHCVSS 7.3EG 7.32025-05-13
Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2025-30701HIGHCVSS 7.3EG 7.32025-04-15
Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account pri…
- CVE-2025-0014HIGHCVSS 7.3EG 7.32025-04-02
Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2023-31360HIGHCVSS 7.3EG 7.32025-02-11
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2024-54131HIGHCVSS 7.3EG 7.32024-12-03
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11…
- CVE-2018-9369HIGHCVSS 7.3EG 7.32024-11-19
In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- CVE-2024-21958HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2024-21957HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21946HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21945HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21939HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2024-21938HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary co…
- CVE-2024-21937HIGHCVSS 7.3EG 7.32024-11-12
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2023-31349HIGHCVSS 7.3EG 7.32024-08-13
Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2023-46870HIGHCVSS 7.3EG 7.32024-05-14
extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code e…
- CVE-2024-32368HIGHCVSS 7.3EG 7.32024-04-22
Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via the Bluetooth Low Energy (BLE) component.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →