CWE-378— Creation of Temporary File With Insecure Permissions
Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.— MITRE CWE catalog
50 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-378page 1 of 1
- CVE-2024-39872CRITICALCVSS 9.6EG 9.62024-07-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated…
- CVE-2026-25265HIGHCVSS 8.8EG 8.82026-09-22
Privilege escalation due to weak configuration while temporary file handling.
- CVE-2025-32438HIGHCVSS 8.8EG 8.82025-04-15
make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default) a local user is able to create a program that will be execu…
- CVE-2025-27148HIGHCVSS 8.8EG 8.82025-02-25
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delet…
- CVE-2025-34352HIGHCVSS 8.5EG 8.52025-12-02
JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent uninstall or update operations. The Remote Assist uninstaller performs …
- CVE-2026-33572HIGHCVSS 8.4EG 8.42026-03-29
OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive informatio…
- CVE-2026-4137HIGHCVSS 7.8EG 7.82026-05-18
In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` func…
- CVE-2025-46685HIGHCVSS 7.8EG 7.82026-01-13
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …
- CVE-2025-38747HIGHCVSS 7.8EG 7.82025-08-06
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of …
- CVE-2024-7358HIGHCVSS 7.8EG 7.82024-08-01
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulat…
- CVE-2024-42052HIGHCVSS 7.8EG 7.82024-07-28
The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a wevtutil.exe file in the fol…
- CVE-2022-24411HIGHCVSS 7.8EG 7.82022-04-12
Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. …
- CVE-2021-25314HIGHCVSS 7.8EG 7.82021-04-14
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local at…
- CVE-2021-29428HIGHCVSS 7.8EG 7.82021-04-13
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege …
- CVE-2016-9485HIGHCVSS 7.8EG 7.82018-07-13
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows ser…
- CVE-2021-25654HIGHCVSS 6.2EG 7.82021-06-25
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
- CVE-2025-4953HIGHCVSS 7.4EG 7.42025-09-16
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build con…
- CVE-2025-7647HIGHCVSS 7.3EG 7.32025-09-27
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. Thi…
- CVE-2026-4822HIGHCVSS 7.0EG 7.02026-03-25
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a manipulation results in creation of tem…
- CVE-2021-1496HIGHCVSS 7.0EG 7.02021-05-06
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the applicatio…
- CVE-2021-1430HIGHCVSS 7.0EG 7.02021-05-06
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the applicatio…
- CVE-2021-1429HIGHCVSS 7.0EG 7.02021-05-06
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the applicatio…
- CVE-2021-1428HIGHCVSS 7.0EG 7.02021-05-06
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the applicatio…
- CVE-2021-1427HIGHCVSS 7.0EG 7.02021-05-06
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the applicatio…
- CVE-2021-1426HIGHCVSS 7.0EG 7.02021-05-06
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the applicatio…
- CVE-2020-27216HIGHCVSS 7.0EG 7.02020-10-23
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated use…
- CVE-2025-46684MEDIUMCVSS 5.5EG 6.62026-01-13
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …
- CVE-2025-55629MEDIUMCVSS 6.5EG 6.52025-08-22
Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords via manipulation of the userName value.
- CVE-2025-32979MEDIUMCVSS 6.5EG 6.52025-04-25
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
- CVE-2024-52543MEDIUMCVSS 6.5EG 6.52024-12-25
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclos…
- CVE-2024-23454MEDIUMCVSS 6.2EG 6.22024-09-25
Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems,…
- CVE-2021-28168MEDIUMCVSS 6.2EG 6.22021-04-22
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the p…
- CVE-2023-6917MEDIUMCVSS 6.0EG 6.02024-02-28
A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP use…
- CVE-2023-26603MEDIUMCVSS 5.9EG 5.92024-04-26
JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.
- CVE-2023-0482MEDIUMCVSS 5.5EG 5.52023-02-17
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
- CVE-2022-24823MEDIUMCVSS 5.5EG 5.52022-05-06
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are us…
- CVE-2021-21290MEDIUMCVSS 5.5EG 5.52021-02-08
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like …
- CVE-2021-21364MEDIUMCVSS 5.3EG 5.32021-03-11
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before versio…
- CVE-2021-21363MEDIUMCVSS 5.3EG 5.32021-03-11
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before versio…
- CVE-2023-28600MEDIUMCVSS 5.2EG 5.22023-06-13
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.
- CVE-2025-9474MEDIUMCVSS 4.5EG 4.52025-08-26
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with in…
- CVE-2026-46388MEDIUMCVSS 4.4EG 4.42026-07-10
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are …
- CVE-2026-2817MEDIUMCVSS 4.4EG 4.42026-02-19
Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extra…
- CVE-2026-97026LOWCVSS 3.9EG 3.92026-09-28
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while in…
- CVE-2023-27408LOWCVSS 3.3EG 3.32023-05-09
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This cou…
- CVE-2023-0481LOWCVSS 3.3EG 3.32023-02-24
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
- CVE-2020-8908LOWCVSS 3.3EG 3.32020-12-10
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(…
- CVE-2026-97025LOWCVSS 3.2EG 3.22026-09-28
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated use…
- CVE-2021-21331LOWCVSS 3.0EG 3.02021-03-03
The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-like system with multiple users.…
- CVE-2024-47884LOWCVSS 2.4EG 2.42024-10-11
foxmarks is a CLI read-only interface for Firefox's bookmarks and history. A temporary file was created under the /tmp directory with read permissions for all users containing a copy of Firefox's database of bookmarks, history, input histo…
Map vulnerabilities like CWE-378 to your infrastructure
EchelonGraph correlates every CVE — across CWE-378 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →