CWE-281— Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.— MITRE CWE catalog
369 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-281page 1 of 8
- CVE-2017-8543CRITICALCVSS 9.8EG 9.8⚠ KEV2017-06-15
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, an…
- CVE-2024-36532CRITICALCVSS 10.0EG 10.02024-06-21
Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-56973CRITICALCVSS 9.8EG 9.82025-02-14
Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.
- CVE-2024-46622CRITICALCVSS 9.8EG 9.82025-01-06
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arbitrary file creation, modification and d…
- CVE-2024-55507CRITICALCVSS 9.8EG 9.82025-01-03
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
- CVE-2024-54465CRITICALCVSS 9.8EG 9.82024-12-12
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.
- CVE-2024-41650CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.
- CVE-2024-41649CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.
- CVE-2024-41648CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.
- CVE-2024-41646CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.
- CVE-2024-41645CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.
- CVE-2024-41644CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.
- CVE-2023-47463CRITICALCVSS 9.8EG 9.82023-11-30
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.
- CVE-2020-36070CRITICALCVSS 9.8EG 9.82023-04-26
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
- CVE-2021-33990CRITICALCVSS 9.8EG 9.82023-04-16
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not de…
- CVE-2023-28668CRITICALCVSS 9.8EG 9.82023-04-02
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
- CVE-2021-29971CRITICALCVSS 9.8EG 9.82021-08-05
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating sys…
- CVE-2020-18890CRITICALCVSS 9.8EG 9.82021-05-06
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
- CVE-2018-4115CRITICALCVSS 9.8EG 9.82018-04-03
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves CFPreferences in the "System Preferences" co…
- CVE-2017-8589CRITICALCVSS 9.8EG 9.82017-07-11
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way…
- CVE-2026-23556CRITICALCVSS 9.4EG 9.42026-07-09
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.
- CVE-2026-39832CRITICALCVSS 9.1EG 9.12026-05-22
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of t…
- CVE-2025-55130CRITICALCVSS 9.1EG 9.12026-01-20
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the curren…
- CVE-2025-43698CRITICALCVSS 9.1EG 9.12025-06-10
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025
- CVE-2024-46310CRITICALCVSS 9.1EG 9.12025-01-13
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
- CVE-2024-54880CRITICALCVSS 9.1EG 9.12025-01-06
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
- CVE-2024-54879CRITICALCVSS 9.1EG 9.12025-01-06
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
- CVE-2023-34034CRITICALCVSS 9.1EG 9.12023-07-19
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
- CVE-2020-10083CRITICALCVSS 9.1EG 9.12020-03-13
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
- CVE-2026-82964HIGHCVSS 8.8EG 8.82026-09-16
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox v…
- CVE-2026-44832HIGHCVSS 8.8EG 8.82026-05-26
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1…
- CVE-2026-24834HIGHCVSS 8.8EG 8.82026-02-19
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the co…
- CVE-2025-34298HIGHCVSS 8.8EG 8.82025-10-30
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization ch…
- CVE-2025-25711HIGHCVSS 8.8EG 8.82025-03-12
An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/admin/updateUser] API endpoint
- CVE-2024-53355HIGHCVSS 8.8EG 8.82025-01-31
Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /…
- CVE-2023-42228HIGHCVSS 8.8EG 8.82025-01-13
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.
- CVE-2024-54818HIGHCVSS 8.8EG 8.82025-01-08
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.
- CVE-2024-50930HIGHCVSS 8.8EG 8.82024-12-10
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
- CVE-2024-50920HIGHCVSS 8.8EG 8.82024-12-10
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
- CVE-2023-6186HIGHCVSS 8.8EG 8.82023-12-11
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command tar…
- CVE-2023-6239HIGHCVSS 8.8EG 8.82023-11-28
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7,…
- CVE-2023-48240HIGHCVSS 8.8EG 8.82023-11-20
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server…
- CVE-2023-4996HIGHCVSS 8.8EG 8.82023-11-06
Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a …
- CVE-2023-41939HIGHCVSS 8.8EG 8.82023-09-06
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they'…
- CVE-2023-34672HIGHCVSS 8.8EG 8.82023-06-23
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.
- CVE-2023-28161HIGHCVSS 8.8EG 8.82023-06-02
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dan…
- CVE-2023-31923HIGHCVSS 8.8EG 8.82023-05-22
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is cau…
- CVE-2022-38473HIGHCVSS 8.8EG 8.82022-12-22
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR <…
- CVE-2019-14841HIGHCVSS 8.8EG 8.82022-10-17
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
- CVE-2022-38577HIGHCVSS 8.8EG 8.82022-09-19
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
Map vulnerabilities like CWE-281 to your infrastructure
EchelonGraph correlates every CVE — across CWE-281 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →