CWE-281— Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.— MITRE CWE catalog
369 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-281page 2 of 8
- CVE-2022-22472HIGHCVSS 8.8EG 8.82022-06-30
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control…
- CVE-2022-1227HIGHCVSS 8.8EG 8.82022-04-29
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'pod…
- CVE-2021-45008HIGHCVSS 8.8EG 8.82022-02-21
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
- CVE-2021-0965HIGHCVSS 8.8EG 8.82021-12-15
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed…
- CVE-2021-32465HIGHCVSS 8.8EG 8.82021-08-04
An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an att…
- CVE-2021-3495HIGHCVSS 8.8EG 8.82021-06-01
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability an…
- CVE-2020-8913HIGHCVSS 8.8EG 8.82020-08-12
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a vict…
- CVE-2020-2025HIGHCVSS 8.8EG 8.82020-05-19
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers…
- CVE-2019-13727HIGHCVSS 8.8EG 8.82019-12-10
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2019-18457HIGHCVSS 8.8EG 8.82019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.
- CVE-2019-13682HIGHCVSS 8.8EG 8.82019-11-25
Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2017-8590HIGHCVSS 8.8EG 8.82017-07-11
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the w…
- CVE-2022-24428HIGHCVSS 6.3EG 8.82022-04-08
Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to …
- CVE-2025-7346HIGHCVSS 8.7EG 8.72025-07-08
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
- CVE-2021-37086HIGHCVSS 8.6EG 8.62021-12-07
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sa…
- CVE-2019-0233HIGHCVSS 7.5EG 8.52020-09-14
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
- CVE-2024-56191HIGHCVSS 8.4EG 8.42025-03-10
In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita…
- CVE-2024-40672HIGHCVSS 8.4EG 8.42025-01-28
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
- CVE-2025-24337HIGHCVSS 8.4EG 8.42025-01-20
WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
- CVE-2022-43910HIGHCVSS 8.4EG 8.42023-07-19
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908.
- CVE-2024-44193HIGHCVSS 7.8EG 8.42024-10-02
A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.
- CVE-2024-40828HIGHCVSS 7.8EG 8.42024-07-29
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious app may be able to gain root privileges.
- CVE-2023-43612HIGHCVSS 7.8EG 8.42023-11-20
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.
- CVE-2024-40821HIGHCVSS 7.1EG 8.42024-07-29
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.
- CVE-2024-40811HIGHCVSS 5.5EG 8.42024-07-29
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.
- CVE-2024-40800HIGHCVSS 5.5EG 8.42024-07-29
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
- CVE-2023-0975HIGHCVSS 8.2EG 8.22023-04-03
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevat…
- CVE-2026-35385HIGHCVSS 8.1EG 8.12026-04-02
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
- CVE-2023-42231HIGHCVSS 8.1EG 8.12025-01-13
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.
- CVE-2024-37882HIGHCVSS 8.1EG 8.12024-06-14
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.…
- CVE-2024-28746HIGHCVSS 8.1EG 8.12024-03-14
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access. …
- CVE-2021-3414HIGHCVSS 8.1EG 8.12022-08-26
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data co…
- CVE-2019-14226HIGHCVSS 8.1EG 8.12019-10-14
OX App Suite through 7.10.2 has Insecure Permissions.
- CVE-2018-5163HIGHCVSS 8.1EG 8.12018-06-11
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code.…
- CVE-2017-8563HIGHCVSS 8.1EG 8.12017-07-11
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerbe…
- CVE-2025-25871HIGHCVSS 8.0EG 8.02025-03-14
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
- CVE-2021-43816HIGHCVSS 8.0EG 8.02022-01-05
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod …
- CVE-2020-8182HIGHCVSS 8.0EG 8.02020-10-05
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
- CVE-2026-47599HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this …
- CVE-2026-47595HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability m…
- CVE-2026-47489HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service,…
- CVE-2026-24194HIGHCVSS 7.8EG 7.82026-05-26
NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privi…
- CVE-2025-69875HIGHCVSS 7.8EG 7.82026-02-03
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined file…
- CVE-2025-43026HIGHCVSS 7.8EG 7.82025-06-05
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
- CVE-2025-31184HIGHCVSS 7.8EG 7.82025-03-31
This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.
- CVE-2025-30456HIGHCVSS 7.8EG 7.82025-03-31
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root…
- CVE-2025-30449HIGHCVSS 7.8EG 7.82025-03-31
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.
- CVE-2024-56192HIGHCVSS 7.8EG 7.82025-03-10
In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede…
- CVE-2023-42867HIGHCVSS 7.8EG 7.82024-12-20
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
- CVE-2024-54515HIGHCVSS 7.8EG 7.82024-12-12
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.
Map vulnerabilities like CWE-281 to your infrastructure
EchelonGraph correlates every CVE — across CWE-281 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →