CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,721 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 3 of 35
- CVE-2020-9409CRITICALCVSS 9.8EG 9.82020-05-20
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an …
- CVE-2020-12834CRITICALCVSS 9.8EG 9.82020-05-15
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-log…
- CVE-2019-20536CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2…
- CVE-2020-9039CRITICALCVSS 9.8EG 9.82020-02-22
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint e…
- CVE-2020-8114CRITICALCVSS 9.8EG 9.82020-02-05
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- CVE-2019-19392CRITICALCVSS 9.8EG 9.82020-01-21
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.
- CVE-2019-8256CRITICALCVSS 9.8EG 9.82019-12-19
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
- CVE-2019-17383CRITICALCVSS 9.8EG 9.82019-10-09
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
- CVE-2019-17124CRITICALCVSS 9.8EG 9.82019-10-09
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
- CVE-2019-12450CRITICALCVSS 9.8EG 9.82019-05-29
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
- CVE-2017-16128CRITICALCVSS 9.8EG 9.82018-06-07
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
- CVE-2017-16127CRITICALCVSS 9.8EG 9.82018-06-07
The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
- CVE-2017-0847CRITICALCVSS 9.8EG 9.82017-11-16
An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.
- CVE-2017-5642CRITICALCVSS 9.8EG 9.82017-04-03
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
- CVE-1999-0426CRITICALCVSS 9.8EG 9.81999-03-01
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
- CVE-2024-51162CRITICALCVSS 8.8EG 9.82024-11-20
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole …
- CVE-2020-14521CRITICALCVSS 8.3EG 9.82022-02-11
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of…
- CVE-2025-24135CRITICALCVSS 7.8EG 9.82025-01-27
This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges.
- CVE-2021-4297CRITICALCVSS 5.5EG 9.82023-01-01
A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the file application/controllers/Restapi.php. The manipulation of the argument sourcefilename …
- CVE-2025-24891CRITICALCVSS 9.6EG 9.62025-01-31
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as root by default, there is no limit to w…
- CVE-2020-6471CRITICALCVSS 9.6EG 9.62020-05-21
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- CVE-2020-6469CRITICALCVSS 9.6EG 9.62020-05-21
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- CVE-2026-47107CRITICALCVSS 8.1EG 9.62026-05-19
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to …
- CVE-2025-27464CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, a…
- CVE-2025-27463CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, a…
- CVE-2025-27462CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor…
- CVE-2023-4088CRITICALCVSS 7.8EG 9.32023-09-20
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and…
- CVE-2026-52766CRITICALCVSS 9.1EG 9.12026-07-09
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array,…
- CVE-2025-49084CRITICALCVSS 9.1EG 9.12025-07-31
CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, …
- CVE-2024-57548CRITICALCVSS 9.1EG 9.12025-01-27
CMSimple 5.16 allows the user to edit log.php file via print page.
- CVE-2024-55959CRITICALCVSS 9.1EG 9.12025-01-21
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
- CVE-2024-46505CRITICALCVSS 9.1EG 9.12025-01-09
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
- CVE-2019-20457CRITICALCVSS 9.1EG 9.12024-11-07
An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorizati…
- CVE-2024-30415CRITICALCVSS 9.1EG 9.12024-04-07
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-29919CRITICALCVSS 9.1EG 9.12023-05-23
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
- CVE-2022-34737CRITICALCVSS 9.1EG 9.12022-07-12
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
- CVE-2021-40053CRITICALCVSS 9.1EG 9.12022-03-10
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
- CVE-2021-39635CRITICALCVSS 9.1EG 9.12022-02-11
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Prod…
- CVE-2021-44140CRITICALCVSS 9.1EG 9.12021-11-24
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance…
- CVE-2021-31217CRITICALCVSS 9.1EG 9.12021-07-13
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
- CVE-2024-7525CRITICALCVSS 8.1EG 9.12024-08-06
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firef…
- CVE-2024-44760CRITICALCVSS 7.5EG 9.12024-08-28
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
- CVE-2024-11703CRITICALCVSS 5.7EG 9.12024-11-26
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
- CVE-2023-42945CRITICALCVSS 5.5EG 9.12024-02-21
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Bluetooth.
- CVE-2022-41943CRITICALCVSS 9.0EG 9.02022-11-22
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default.…
- CVE-2017-11610CRITICALCVSS 8.8EG 9.02017-08-23
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord name…
- CVE-2026-77393HIGHCVSS 8.8EG 8.82026-09-04
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Desi…
- CVE-2026-75166HIGHCVSS 8.8EG 8.82026-09-04
Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attac…
- CVE-2023-54366HIGHCVSS 8.8EG 8.82026-07-18
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on public…
- CVE-2026-12602HIGHCVSS 8.8EG 8.82026-06-22
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other …
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →