CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 12 of 34
- CVE-2021-22538MEDIUMCVSS 6.3EG 6.32021-03-31
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious …
- CVE-2021-22571MEDIUMCVSS 5.5EG 5.52022-03-18
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
- CVE-2021-22817HIGHCVSS 7.8EG 7.82022-02-09
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo…
- CVE-2021-23166HIGHCVSS 8.7EG 8.72023-04-25
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
- CVE-2021-24031MEDIUMCVSS 5.5EG 5.52021-03-04
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writ…
- CVE-2021-24032MEDIUMCVSS 4.7EG 4.72021-03-04
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files co…
- CVE-2021-25317LOWCVSS 3.3EG 3.32021-05-05
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of…
- CVE-2021-25319HIGHCVSS 7.8EG 7.82021-05-05
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and pri…
- CVE-2021-25344MEDIUMCVSS 6.2EG 6.22021-03-04
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.
- CVE-2021-25355MEDIUMCVSS 5.5EG 5.52021-03-25
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
- CVE-2021-25358MEDIUMCVSS 4.0EG 4.02021-04-09
A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.
- CVE-2021-25359MEDIUMCVSS 4.0EG 4.02021-04-09
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.
- CVE-2021-25381MEDIUMCVSS 5.5EG 5.52021-04-09
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingInt…
- CVE-2021-26274HIGHCVSS 7.1EG 7.12021-07-07
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
- CVE-2021-26804MEDIUMCVSS 6.5EG 6.52021-05-04
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of th…
- CVE-2021-27032HIGHCVSS 7.8EG 7.82021-05-28
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and a…
- CVE-2021-27193CRITICALCVSS 9.8EG 9.82021-03-25
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege esc…
- CVE-2021-27285HIGHCVSS 8.4EG 8.42025-01-06
An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.
- CVE-2021-28098HIGHCVSS 7.8EG 7.82021-04-14
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMD…
- CVE-2021-28271HIGHCVSS 8.8EG 8.82021-04-27
Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions …
- CVE-2021-28649HIGHCVSS 7.3EG 7.32021-05-12
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have t…
- CVE-2021-29005HIGHCVSS 8.8EG 8.82021-10-11
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
- CVE-2021-29052MEDIUMCVSS 4.3EG 4.32021-05-17
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authent…
- CVE-2021-30490HIGHCVSS 7.8EG 7.82022-08-16
upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.
- CVE-2021-30493MEDIUMCVSS 5.5EG 5.52021-04-14
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log fil…
- CVE-2021-30494MEDIUMCVSS 5.5EG 5.52021-04-14
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log fi…
- CVE-2021-30750MEDIUMCVSS 5.5EG 5.52021-09-08
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.
- CVE-2021-30999MEDIUMCVSS 4.3EG 4.32021-08-24
The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be unable to fully delete browsing history.
- CVE-2021-31000LOWCVSS 3.3EG 3.32021-08-24
A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1, tvOS 15.2. A malicious application may be able to read sensitive contact information.
- CVE-2021-31006MEDIUMCVSS 5.5EG 5.52021-08-24
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicious application may be able to bypass certain Privacy preferences.
- CVE-2021-31007MEDIUMCVSS 5.5EG 5.52021-08-24
Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11.6.2, watchOS 8.1, macOS Monterey 12.1. A malicious application may be able to bypass Priv…
- CVE-2021-31217CRITICALCVSS 9.1EG 9.12021-07-13
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
- CVE-2021-31519HIGHCVSS 7.3EG 7.32021-05-12
An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder an…
- CVE-2021-3155LOWCVSS 3.8EG 3.82022-02-17
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.…
- CVE-2021-31822HIGHCVSS 7.8EG 7.82021-11-24
When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the contents of the systemd service file to gain privileged acce…
- CVE-2021-3187HIGHCVSS 8.8EG 8.82023-12-11
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time…
- CVE-2021-31998MEDIUMCVSS 6.8EG 6.82021-06-10
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root.…
- CVE-2021-32006MEDIUMCVSS 5.0EG 5.02022-03-10
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup fi…
- CVE-2021-32464HIGHCVSS 7.8EG 7.82021-08-04
An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Pleas…
- CVE-2021-32725LOWCVSS 3.5EG 3.52021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in ver…
- CVE-2021-33038HIGHCVSS 7.5EG 7.52021-05-26
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive i…
- CVE-2021-33062HIGHCVSS 7.8EG 7.82021-11-17
Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33071HIGHCVSS 7.8EG 7.82021-11-17
Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33088HIGHCVSS 7.8EG 7.82021-11-17
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33090HIGHCVSS 7.8EG 7.82021-11-17
Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC10i5FN, NUC10i7FN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privile…
- CVE-2021-33092HIGHCVSS 7.8EG 7.82021-11-17
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before version 2.2.1.383 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33129HIGHCVSS 7.8EG 7.82022-02-09
Incorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33166MEDIUMCVSS 5.5EG 5.52022-02-09
Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2021-33214MEDIUMCVSS 6.1EG 6.12021-07-09
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
- CVE-2021-33324MEDIUMCVSS 4.3EG 4.32021-08-03
The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a p…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →