CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 13 of 34
- CVE-2021-33327MEDIUMCVSS 4.3EG 4.32021-08-03
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated use…
- CVE-2021-33333MEDIUMCVSS 6.3EG 6.32021-08-03
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to v…
- CVE-2021-33334MEDIUMCVSS 4.3EG 4.32021-08-03
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with …
- CVE-2021-33506HIGHCVSS 7.5EG 7.52021-05-26
jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation.
- CVE-2021-33923MEDIUMCVSS 5.5EG 5.52021-09-29
Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).
- CVE-2021-3394HIGHCVSS 8.8EG 8.82021-02-09
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.
- CVE-2021-34164HIGHCVSS 8.8EG 8.82023-02-17
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location.
- CVE-2021-34182CRITICALCVSS 9.8EG 9.82023-02-17
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
- CVE-2021-3437CRITICALCVSS 9.8EG 9.82022-12-12
Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. HP is releasing software updates to mitigate the potential vulnerabilities.
- CVE-2021-34387MEDIUMCVSS 6.3EG 6.32021-06-21
The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which…
- CVE-2021-34395LOWCVSS 3.9EG 3.92021-06-22
Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcation…
- CVE-2021-3451MEDIUMCVSS 5.5EG 5.52021-04-27
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.
- CVE-2021-3462HIGHCVSS 5.5EG 7.82021-04-13
A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.
- CVE-2021-35312HIGHCVSS 7.8EG 7.82021-08-06
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be…
- CVE-2021-3579HIGHCVSS 7.8EG 7.82021-10-28
Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHO…
- CVE-2021-36363CRITICALCVSS 9.8EG 9.82021-09-28
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
- CVE-2021-36365CRITICALCVSS 9.8EG 9.82021-09-28
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
- CVE-2021-36397MEDIUMCVSS 5.3EG 5.32023-03-06
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
- CVE-2021-36400MEDIUMCVSS 5.3EG 5.32023-03-06
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
- CVE-2021-36781MEDIUMCVSS 5.9EG 5.92022-01-14
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec ver…
- CVE-2021-36795HIGHCVSS 7.8EG 7.82021-08-06
A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An underprivileged linux user, if certain environment criteria are met, can gain additional privi…
- CVE-2021-36989CRITICALCVSS 9.8EG 9.82021-10-28
There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
- CVE-2021-36990CRITICALCVSS 9.8EG 9.82021-10-28
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
- CVE-2021-37000HIGHCVSS 7.7EG 7.72024-12-28
Some Huawei wearables have a permission management vulnerability.
- CVE-2021-3701MEDIUMCVSS 6.6EG 6.62022-08-23
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or f…
- CVE-2021-37030HIGHCVSS 7.5EG 7.52021-11-23
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- CVE-2021-37103MEDIUMCVSS 5.5EG 5.52022-02-25
There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-37132MEDIUMCVSS 5.3EG 5.32022-01-03
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
- CVE-2021-37167CRITICALCVSS 9.8EG 9.82021-08-02
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root acc…
- CVE-2021-3720MEDIUMCVSS 5.5EG 5.52021-11-12
An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.
- CVE-2021-3722MEDIUMCVSS 5.0EG 5.02022-04-22
A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to non-standard locations during installation.
- CVE-2021-37289HIGHCVSS 7.2EG 7.22022-08-22
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.
- CVE-2021-37351MEDIUMCVSS 5.3EG 5.32021-08-13
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
- CVE-2021-37363HIGHCVSS 7.8EG 7.82021-10-26
An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving…
- CVE-2021-38268MEDIUMCVSS 6.5EG 6.52022-03-02
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members,…
- CVE-2021-38379MEDIUMCVSS 5.5EG 5.52021-10-27
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
- CVE-2021-38420HIGHCVSS 7.8EG 7.82021-11-03
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.
- CVE-2021-38557HIGHCVSS 8.8EG 8.82021-08-24
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data accou…
- CVE-2021-39087MEDIUMCVSS 6.5EG 6.52022-08-16
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force I…
- CVE-2021-3917MEDIUMCVSS 5.5EG 5.52022-08-23
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest thr…
- CVE-2021-39273HIGHCVSS 8.8EG 8.82021-08-19
In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution wi…
- CVE-2021-39274CRITICALCVSS 9.8EG 9.82021-08-19
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file. This results in arbitrary co…
- CVE-2021-3948MEDIUMCVSS 6.3EG 6.32022-02-18
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integ…
- CVE-2021-39635CRITICALCVSS 9.1EG 9.12022-02-11
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Prod…
- CVE-2021-39639MEDIUMCVSS 6.8EG 6.82021-12-15
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. Us…
- CVE-2021-39651HIGHCVSS 7.8EG 7.82021-12-15
In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2021-39658CRITICALCVSS 9.8EG 9.82022-02-11
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to …
- CVE-2021-39662HIGHCVSS 7.8EG 7.82022-02-11
In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privi…
- CVE-2021-39694HIGHCVSS 7.8EG 7.82022-03-16
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges ne…
- CVE-2021-39706HIGHCVSS 7.8EG 7.82022-03-16
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →