CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 15 of 34
- CVE-2021-45335HIGHCVSS 8.8EG 8.82021-12-27
Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.
- CVE-2021-46085MEDIUMCVSS 6.5EG 6.52022-01-25
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.
- CVE-2021-46086HIGHCVSS 7.5EG 7.52022-01-25
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker ca…
- CVE-2021-46093CRITICALCVSS 9.8EG 9.82022-02-01
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
- CVE-2021-46270LOWCVSS 2.7EG 2.72022-03-02
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
- CVE-2021-46811MEDIUMCVSS 5.3EG 5.32022-06-13
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
- CVE-2021-46834MEDIUMCVSS 5.5EG 5.52022-09-20
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).
- CVE-2021-47761HIGHCVSS 7.8EG 7.82026-01-15
MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which wi…
- CVE-2021-47852HIGHCVSS 8.8EG 8.82026-01-21
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary …
- CVE-2022-0336HIGHCVSS 8.8EG 8.82022-08-29
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds …
- CVE-2022-0486HIGHCVSS 4.4EG 7.82022-05-17
Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of pri…
- CVE-2022-0997HIGHCVSS 3.9EG 7.82022-05-17
Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitra…
- CVE-2022-1038HIGHCVSS 7.8EG 7.82022-12-12
A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.
- CVE-2022-1109HIGHCVSS 5.5EG 7.52023-01-20
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
- CVE-2022-1833HIGHCVSS 8.8EG 8.82022-06-21
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. …
- CVE-2022-20004HIGHCVSS 7.8EG 7.82022-05-10
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2022-20137HIGHCVSS 7.3EG 7.32022-06-15
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges …
- CVE-2022-20240LOWCVSS 2.3EG 2.32022-12-13
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User in…
- CVE-2022-20246HIGHCVSS 7.8EG 7.82022-08-11
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges…
- CVE-2022-20255MEDIUMCVSS 4.4EG 4.42022-08-12
In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- CVE-2022-20259MEDIUMCVSS 5.5EG 5.52022-08-12
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod…
- CVE-2022-20261LOWCVSS 2.3EG 2.32022-08-12
In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita…
- CVE-2022-20263MEDIUMCVSS 5.5EG 5.52022-08-12
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed …
- CVE-2022-20267LOWCVSS 3.3EG 3.32022-08-12
In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2022-20272MEDIUMCVSS 5.5EG 5.52022-08-12
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is neede…
- CVE-2022-20281HIGHCVSS 7.8EG 7.82022-08-12
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…
- CVE-2022-20294MEDIUMCVSS 5.5EG 5.52022-08-12
In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed fo…
- CVE-2022-20295MEDIUMCVSS 5.5EG 5.52022-08-12
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed…
- CVE-2022-20296MEDIUMCVSS 5.5EG 5.52022-08-12
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed…
- CVE-2022-20298MEDIUMCVSS 5.5EG 5.52022-08-12
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed…
- CVE-2022-20299MEDIUMCVSS 5.5EG 5.52022-08-12
In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not…
- CVE-2022-20300MEDIUMCVSS 5.5EG 5.52022-08-12
In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed…
- CVE-2022-20301MEDIUMCVSS 5.5EG 5.52022-08-12
In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for ex…
- CVE-2022-20303MEDIUMCVSS 5.5EG 5.52022-08-12
In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed…
- CVE-2022-20305LOWCVSS 3.3EG 3.32022-08-12
In ContentService, there is a possible disclosure of available account types due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for explo…
- CVE-2022-20310LOWCVSS 3.3EG 3.32022-08-12
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed …
- CVE-2022-20311LOWCVSS 3.3EG 3.32022-08-12
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed …
- CVE-2022-20312MEDIUMCVSS 5.5EG 5.52022-08-12
In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is …
- CVE-2022-20315LOWCVSS 3.3EG 3.32022-08-12
In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for …
- CVE-2022-20322MEDIUMCVSS 5.5EG 5.52022-08-12
In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2022-20327LOWCVSS 2.8EG 2.82022-08-12
In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed f…
- CVE-2022-20328LOWCVSS 3.3EG 3.32022-08-12
In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not …
- CVE-2022-20341MEDIUMCVSS 5.5EG 5.52022-08-12
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User inter…
- CVE-2022-20348HIGHCVSS 7.8EG 7.82022-08-10
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileg…
- CVE-2022-20349HIGHCVSS 7.8EG 7.82022-08-10
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2022-20352MEDIUMCVSS 5.5EG 5.52022-08-10
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additiona…
- CVE-2022-20358LOWCVSS 3.3EG 3.32022-08-10
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges ne…
- CVE-2022-20360HIGHCVSS 7.8EG 7.82022-08-10
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed f…
- CVE-2022-20435HIGHCVSS 7.8EG 7.82022-10-11
There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android SoCAndroid ID: A-2…
- CVE-2022-20436HIGHCVSS 7.8EG 7.82022-10-11
There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →