CWE-377— Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.— MITRE CWE catalog
110 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-377page 3 of 3
- CVE-2026-4822HIGHCVSS 7.0EG 7.02026-03-25
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a manipulation results in creation of tem…
- CVE-2026-49134HIGHCVSS 7.1EG 7.12026-06-01
CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates …
- CVE-2026-49135HIGHCVSS 7.1EG 7.12026-06-01
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization…
- CVE-2026-53759LOWCVSS 2.0EG 2.02026-07-06
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed attac…
- CVE-2026-55086MEDIUMCVSS 4.2EG 4.22026-08-13
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared worl…
- CVE-2026-62294MEDIUMCVSS 5.1EG 5.12026-07-15
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local …
- CVE-2026-63404HIGHCVSS 7.3EG 7.32026-08-25
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and esca…
- CVE-2026-73584MEDIUMCVSS 6.3EG 6.32026-08-13
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the atta…
- CVE-2026-73585MEDIUMCVSS 6.3EG 6.32026-08-13
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can r…
- CVE-2026-75920MEDIUMCVSS 5.3EG 5.32026-08-19
phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the t…
Map vulnerabilities like CWE-377 to your infrastructure
EchelonGraph correlates every CVE — across CWE-377 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →