CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,721 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 20 of 35
- CVE-2021-41637HIGHCVSS 7.1EG 7.12022-06-24
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
- CVE-2021-45083HIGHCVSS 7.1EG 7.12022-02-20
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.dig…
- CVE-2021-26274HIGHCVSS 7.1EG 7.12021-07-07
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
- CVE-2021-1056HIGHCVSS 7.1EG 7.12021-01-08
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which ma…
- CVE-2019-11155HIGHCVSS 7.1EG 7.12019-11-14
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.
- CVE-2019-4652HIGHCVSS 7.1EG 7.12019-11-12
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170…
- CVE-2019-5687HIGHCVSS 7.1EG 7.12019-08-06
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default permissions for an object exposes it to an unintended actor
- CVE-2017-12699HIGHCVSS 7.1EG 7.12017-09-09
An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.
- CVE-2017-1382HIGHCVSS 7.1EG 7.12017-07-24
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to file…
- CVE-2020-36652HIGHCVSS 6.6EG 7.12023-02-28
Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automa…
- CVE-2020-36611HIGHCVSS 6.6EG 7.12023-01-17
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS, Hitachi Tuning Manager - Agent for SAN Switch c…
- CVE-2023-25540HIGHCVSS 6.0EG 7.12023-02-28
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service.
- CVE-2024-27888HIGHCVSS 5.5EG 7.12024-07-29
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sonoma 14.4. An app may be able to modify protected parts of the file system.
- CVE-2026-9634HIGHCVSS 7.0EG 7.02026-09-01
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administ…
- CVE-2026-9633HIGHCVSS 7.0EG 7.02026-09-01
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-adminis…
- CVE-2026-78553HIGHCVSS 7.0EG 7.02026-08-24
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as 0644 under a common 0…
- CVE-2025-48512HIGHCVSS 7.0EG 7.02026-05-15
Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
- CVE-2025-13905HIGHCVSS 7.0EG 7.02026-01-29
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal …
- CVE-2025-61667HIGHCVSS 7.0EG 7.02025-11-12
The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due to insufficient permissions being set on the `opt/datadog-age…
- CVE-2025-43887HIGHCVSS 7.0EG 7.02025-09-10
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation o…
- CVE-2025-53945HIGHCVSS 7.0EG 7.02025-07-18
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. V…
- CVE-2024-49724HIGHCVSS 7.0EG 7.02025-01-21
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privi…
- CVE-2024-27134HIGHCVSS 7.0EG 7.02024-11-25
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when t…
- CVE-2024-49504HIGHCVSS 7.0EG 7.02024-11-13
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
- CVE-2024-22428HIGHCVSS 7.0EG 7.02024-01-16
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommen…
- CVE-2022-33877HIGHCVSS 7.0EG 7.02023-06-13
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a lo…
- CVE-2023-28079HIGHCVSS 7.0EG 7.02023-05-30
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in t…
- CVE-2022-4568HIGHCVSS 7.0EG 7.02023-05-01
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
- CVE-2019-7588HIGHCVSS 6.7EG 7.02019-06-18
A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be achieved. This vulnerability impacts exacqVision ESM v5.12.2 and all prior versions of ESM …
- CVE-2022-31251HIGHCVSS 6.5EG 7.02022-09-07
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prio…
- CVE-2025-48516MEDIUMCVSS 6.9EG 6.92026-05-15
Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect t…
- CVE-2025-62661MEDIUMCVSS 6.9EG 6.92025-10-21
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mediawiki - T…
- CVE-2025-62668MEDIUMCVSS 6.9EG 6.92025-10-18
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.
- CVE-2024-12564MEDIUMCVSS 6.9EG 6.92024-12-12
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default settings allows unauthorized users to visit prometheus metrics …
- CVE-2026-65940MEDIUMCVSS 6.8EG 6.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
- CVE-2025-15642MEDIUMCVSS 6.8EG 6.82026-06-17
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DAC…
- CVE-2026-36742MEDIUMCVSS 6.8EG 6.82026-05-13
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).
- CVE-2025-20984MEDIUMCVSS 6.8EG 6.82025-06-04
Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.
- CVE-2025-27521MEDIUMCVSS 6.8EG 6.82025-03-04
Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-50657MEDIUMCVSS 6.8EG 6.82024-11-22
An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method
- CVE-2024-34011MEDIUMCVSS 6.8EG 6.82024-04-29
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758.
- CVE-2024-2859MEDIUMCVSS 6.8EG 6.82024-04-27
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.
- CVE-2022-27651MEDIUMCVSS 6.8EG 6.82022-04-04
A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabiliti…
- CVE-2021-39639MEDIUMCVSS 6.8EG 6.82021-12-15
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. Us…
- CVE-2021-42055MEDIUMCVSS 6.8EG 6.82021-10-18
ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.
- CVE-2021-31998MEDIUMCVSS 6.8EG 6.82021-06-10
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root.…
- CVE-2020-22475MEDIUMCVSS 6.8EG 6.82021-02-22
"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application component allows arbitrary applications on a device to add tasks with no restrictions.
- CVE-2020-28044MEDIUMCVSS 6.8EG 6.82020-11-02
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.
- CVE-2020-13468MEDIUMCVSS 6.8EG 6.82020-08-31
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
- CVE-2018-21061MEDIUMCVSS 6.8EG 6.82020-04-08
An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical functions in the locked state. The Samsung ID is SVE-2016-6341 (August 2018).
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →