CWE-277— Insecure Inherited Permissions
A product defines a set of insecure permissions that are inherited by objects that are created by the program.— MITRE CWE catalog
74 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-277page 1 of 2
- CVE-2024-36540CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-36539CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2021-41170CRITICALCVSS 9.8EG 9.82021-11-08
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue a…
- CVE-2025-11554HIGHCVSS 8.8EG 8.82025-10-09
A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipul…
- CVE-2024-42681HIGHCVSS 8.8EG 8.82024-08-15
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
- CVE-2024-36542HIGHCVSS 8.8EG 8.82024-07-25
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-39877HIGHCVSS 8.8EG 8.82024-07-17
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according…
- CVE-2024-6605HIGHCVSS 8.8EG 8.82024-07-09
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
- CVE-2023-27842HIGHCVSS 8.8EG 8.82023-03-21
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent
- CVE-2024-34329HIGHCVSS 8.4EG 8.42024-07-22
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.
- CVE-2024-29417HIGHCVSS 8.4EG 8.42024-05-03
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.
- CVE-2025-58437HIGHCVSS 8.1EG 8.12025-09-06
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automati…
- CVE-2024-27834HIGHCVSS 5.5EG 8.12024-05-14
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may …
- CVE-2026-30266HIGHCVSS 7.8EG 7.82026-04-20
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file
- CVE-2024-27848HIGHCVSS 7.8EG 7.82024-06-10
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.
- CVE-2024-27822HIGHCVSS 7.8EG 7.82024-05-14
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.
- CVE-2024-26574HIGHCVSS 7.8EG 7.82024-04-08
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe
- CVE-2024-27674HIGHCVSS 7.8EG 7.82024-04-03
Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivileged user can escalate to SYSTEM by replacing the MacroService.exe binary.
- CVE-2024-23233HIGHCVSS 7.8EG 7.82024-03-08
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
- CVE-2023-33990HIGHCVSS 7.8EG 7.82023-07-11
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory ob…
- CVE-2024-27825HIGHCVSS 7.1EG 7.82024-05-14
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.
- CVE-2023-33870HIGHCVSS 6.7EG 7.82024-02-14
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36377HIGHCVSS 6.7EG 7.82022-11-11
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privil…
- CVE-2025-20008HIGHCVSS 7.7EG 7.72025-05-13
Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-41601HIGHCVSS 7.5EG 7.52024-07-19
Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
- CVE-2023-34391HIGHCVSS 7.4EG 7.42023-08-31
Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecu…
- CVE-2024-27847HIGHCVSS 5.5EG 7.42024-05-14
This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to bypass Privacy preferences.
- CVE-2020-5343HIGHCVSS 7.3EG 7.32020-05-04
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vul…
- CVE-2025-37174HIGHCVSS 7.2EG 7.22026-01-13
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to …
- CVE-2026-9046HIGHCVSS 7.0EG 7.02026-07-16
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local …
- CVE-2025-32797HIGHCVSS 7.0EG 7.02025-06-16
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), al…
- CVE-2025-64185MEDIUMCVSS 6.9EG 6.92025-11-20
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
- CVE-2025-29982MEDIUMCVSS 6.8EG 6.82025-04-02
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
- CVE-2025-32092MEDIUMCVSS 6.7EG 6.72026-02-10
Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with …
- CVE-2025-24327MEDIUMCVSS 6.7EG 6.72025-11-11
Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated use…
- CVE-2025-3473MEDIUMCVSS 6.7EG 6.72025-06-11
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
- CVE-2025-20629MEDIUMCVSS 6.7EG 6.72025-05-13
Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-51448MEDIUMCVSS 6.7EG 6.72025-01-18
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-pri…
- CVE-2024-36294MEDIUMCVSS 6.7EG 6.72024-11-13
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-36276MEDIUMCVSS 6.7EG 6.72024-11-13
Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-25561MEDIUMCVSS 6.7EG 6.72024-08-14
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-23908MEDIUMCVSS 6.7EG 6.72024-08-14
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-7143MEDIUMCVSS 6.7EG 6.72024-08-07
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method …
- CVE-2024-21835MEDIUMCVSS 6.7EG 6.72024-05-16
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-45736MEDIUMCVSS 6.7EG 6.72024-05-16
Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-38541MEDIUMCVSS 6.7EG 6.72024-01-19
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via loc…
- CVE-2023-39230MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-34997MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-34314MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41700MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
Map vulnerabilities like CWE-277 to your infrastructure
EchelonGraph correlates every CVE — across CWE-277 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →