CWE-379— Creation of Temporary File in Directory with Insecure Permissions
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.— MITRE CWE catalog
66 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-379page 1 of 2
- CVE-2026-14551HIGHCVSS 8.8EG 8.82026-07-22
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), runnin…
- CVE-2025-32438HIGHCVSS 8.8EG 8.82025-04-15
make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default) a local user is able to create a program that will be execu…
- CVE-2025-27148HIGHCVSS 8.8EG 8.82025-02-25
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delet…
- CVE-2024-36821HIGHCVSS 6.8EG 8.82024-06-11
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
- CVE-2026-86836HIGHCVSS 8.4EG 8.42026-09-14
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a direc…
- CVE-2026-85028HIGHCVSS 7.8EG 7.82026-09-03
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privil…
- CVE-2024-9950HIGHCVSS 7.8EG 7.82025-01-02
A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
- CVE-2024-9500HIGHCVSS 7.8EG 7.82024-11-15
A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.
- CVE-2023-6080HIGHCVSS 7.8EG 7.82024-10-18
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.
- CVE-2023-3181HIGHCVSS 7.8EG 7.82024-01-25
The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM…
- CVE-2023-49797HIGHCVSS 7.8EG 7.82023-12-09
PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged process, may be tricked by an unprivileged attacker into deleting files the unprivileged use…
- CVE-2023-3972HIGHCVSS 7.8EG 7.82023-11-01
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been…
- CVE-2023-37243HIGHCVSS 7.8EG 7.82023-10-31
The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Window…
- CVE-2023-26396HIGHCVSS 7.8EG 7.82023-04-12
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the con…
- CVE-2023-21612HIGHCVSS 7.8EG 7.82023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in pri…
- CVE-2023-21611HIGHCVSS 7.8EG 7.82023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in pri…
- CVE-2021-21100HIGHCVSS 7.8EG 7.82021-04-15
Adobe Digital Editions version 4.5.11.187245 (and earlier) is affected by a Privilege Escalation vulnerability during installation. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary file system write in the…
- CVE-2021-29428HIGHCVSS 7.8EG 7.82021-04-13
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege …
- CVE-2016-9486HIGHCVSS 7.8EG 7.82018-07-13
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows ser…
- CVE-2026-12555HIGHCVSS 7.7EG 7.72026-08-24
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential v…
- CVE-2022-23950HIGHCVSS 7.5EG 7.52022-09-21
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
- CVE-2020-11979HIGHCVSS 7.5EG 7.52020-10-01
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new o…
- CVE-2021-28613HIGHCVSS 7.4EG 7.42021-09-27
Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that could allow an attacker to arbitrarily overwrite a file. Exploitation of this issue requires local access, administrator p…
- CVE-2026-7539HIGHCVSS 7.3EG 7.32026-06-24
A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to …
- CVE-2026-54328HIGHCVSS 7.3EG 7.32026-06-17
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a…
- CVE-2024-7562HIGHCVSS 7.3EG 7.32025-06-12
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and Install…
- CVE-2025-21173HIGHCVSS 7.3EG 7.32025-01-14
.NET Elevation of Privilege Vulnerability
- CVE-2021-40708HIGHCVSS 7.3EG 7.32021-09-29
Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute ar…
- CVE-2021-36002HIGHCVSS 5.0EG 7.32021-09-01
Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. The attacker must…
- CVE-2024-24693HIGHCVSS 7.2EG 7.22024-03-13
Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.
- CVE-2026-69482HIGHCVSS 7.1EG 7.12026-09-08
Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.
- CVE-2026-82346HIGHCVSS 7.0EG 7.02026-08-31
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
- CVE-2025-10279HIGHCVSS 7.0EG 7.02026-02-02
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exp…
- CVE-2020-27216HIGHCVSS 7.0EG 7.02020-10-23
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated use…
- CVE-2021-40776HIGHCVSS 6.1EG 7.02022-06-15
Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interactio…
- CVE-2025-71176MEDIUMCVSS 6.8EG 6.82026-01-22
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
- CVE-2026-63693MEDIUMCVSS 6.6EG 6.62026-08-24
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
- CVE-2026-42191MEDIUMCVSS 6.5EG 6.52026-05-12
OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Exporter.OpenTelemetryProtocol silently fell back to Path.GetTemp…
- CVE-2021-39827MEDIUMCVSS 6.5EG 6.52021-09-27
Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary file write vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to write an arbitrary file to the syste…
- CVE-2020-8831MEDIUMCVSS 6.5EG 6.52020-04-22
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise…
- CVE-2021-28568MEDIUMCVSS 5.8EG 6.52021-09-08
Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during installation process. A local authenticated attacker could leverage this vulnerability to achieve privilege escalation in the …
- CVE-2026-50544MEDIUMCVSS 6.3EG 6.32026-08-12
NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\co…
- CVE-2021-31411MEDIUMCVSS 6.3EG 6.32021-05-05
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0…
- CVE-2021-28168MEDIUMCVSS 6.2EG 6.22021-04-22
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the p…
- CVE-2019-25677MEDIUMCVSS 5.5EG 6.22026-04-05
WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archiv…
- CVE-2025-32802MEDIUMCVSS 6.1EG 6.12025-05-28
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control so…
- CVE-2023-32450MEDIUMCVSS 6.1EG 6.12023-07-27
Dell Power Manager, Versions 3.3 to 3.14 contains an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.
- CVE-2021-28633MEDIUMCVSS 6.1EG 6.12021-08-24
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file creation vulnerability. An attacker could leverage this vulnerability to cause arbitrary file overwriting in the conte…
- CVE-2021-21068MEDIUMCVSS 6.1EG 6.12021-03-12
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a file handling vulnerability that could allow an attacker to cause arbitrary file overwriting. Exploitation of this issue requires physical access and user …
- CVE-2013-1815MEDIUMCVSS 6.1EG 6.12013-04-10
A flaw was found in PackStack. This vulnerability allows a local user to modify deployed systems by changing the answer file, which is created in insecure directories such as /tmp or the current working directory. This insecure file creati…
Map vulnerabilities like CWE-379 to your infrastructure
EchelonGraph correlates every CVE — across CWE-379 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →