CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 17 of 34
- CVE-2022-2735HIGHCVSS 7.8EG 7.82022-09-06
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for…
- CVE-2022-27500MEDIUMCVSS 5.5EG 5.52022-08-18
Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-27649HIGHCVSS 7.5EG 7.52022-04-04
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process…
- CVE-2022-27650HIGHCVSS 7.5EG 7.52022-04-04
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process cap…
- CVE-2022-27651MEDIUMCVSS 6.8EG 6.82022-04-04
A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabiliti…
- CVE-2022-27652MEDIUMCVSS 5.3EG 5.32022-04-18
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabi…
- CVE-2022-27773CRITICALCVSS 9.8EG 9.82022-12-05
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.
- CVE-2022-27840MEDIUMCVSS 4.4EG 4.42022-04-11
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.
- CVE-2022-27919CRITICALCVSS 9.8EG 9.82022-03-25
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.
- CVE-2022-27958MEDIUMCVSS 5.4EG 5.42022-04-10
Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers to access and arbitrarily modify users' personal information.
- CVE-2022-27960MEDIUMCVSS 5.4EG 5.42022-04-10
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
- CVE-2022-28218MEDIUMCVSS 5.5EG 5.52022-04-26
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication …
- CVE-2022-28702HIGHCVSS 6.1EG 7.82022-06-02
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
- CVE-2022-28932CRITICALCVSS 9.8EG 9.82022-05-23
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
- CVE-2022-28999HIGHCVSS 8.8EG 8.82022-05-23
Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe.
- CVE-2022-29162MEDIUMCVSS 5.9EG 5.92022-05-17
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilit…
- CVE-2022-29178HIGHCVSS 8.8EG 8.82022-05-20
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissions vulnerability. …
- CVE-2022-29376HIGHCVSS 8.8EG 8.82022-05-23
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.
- CVE-2022-29483HIGHCVSS 7.8EG 7.82022-06-02
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
- CVE-2022-29547HIGHCVSS 7.5EG 7.52022-04-21
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.
- CVE-2022-29585HIGHCVSS 7.5EG 7.52022-04-28
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the inst…
- CVE-2022-29909HIGHCVSS 8.8EG 8.82022-12-22
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunde…
- CVE-2022-30338MEDIUMCVSS 6.7EG 6.72023-05-10
Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-30355CRITICALCVSS 9.8EG 9.82024-10-25
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
- CVE-2022-30367MEDIUMCVSS 6.5EG 6.52022-05-13
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
- CVE-2022-30375MEDIUMCVSS 6.5EG 6.52022-05-13
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
- CVE-2022-30594HIGHCVSS 7.8EG 7.82022-05-12
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
- CVE-2022-30747MEDIUMCVSS 5.5EG 5.52022-06-07
PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.
- CVE-2022-30753LOWCVSS 3.3EG 3.32022-07-12
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
- CVE-2022-30758MEDIUMCVSS 4.0EG 5.52022-07-12
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.
- CVE-2022-30759HIGHCVSS 8.8EG 8.82023-05-02
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.
- CVE-2022-3101MEDIUMCVSS 5.5EG 5.52023-03-23
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and …
- CVE-2022-31071LOWCVSS 2.5EG 2.52022-06-15
Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) in…
- CVE-2022-31072LOWCVSS 2.5EG 2.52022-06-15
Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 066…
- CVE-2022-31244HIGHCVSS 7.8EG 7.82023-04-25
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
- CVE-2022-31251HIGHCVSS 6.5EG 7.02022-09-07
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prio…
- CVE-2022-31254HIGHCVSS 7.8EG 7.82023-02-07
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows …
- CVE-2022-3146MEDIUMCVSS 5.5EG 5.52023-03-23
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and …
- CVE-2022-31500HIGHCVSS 7.8EG 7.82022-06-02
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
- CVE-2022-3155HIGHCVSS 7.8EG 7.82022-12-22
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started i…
- CVE-2022-32207CRITICALCVSS 9.8EG 9.82022-07-07
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accident…
- CVE-2022-32562HIGHCVSS 8.8EG 8.82022-06-13
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
- CVE-2022-3263HIGHCVSS 7.8EG 7.82022-09-23
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.
- CVE-2022-32743HIGHCVSS 7.5EG 7.52022-09-01
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
- CVE-2022-33023HIGHCVSS 7.5EG 7.52022-06-29
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
- CVE-2022-33175CRITICALCVSS 9.8EG 9.82022-06-13
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to discl…
- CVE-2022-33182HIGHCVSS 7.8EG 7.82022-10-25
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “…
- CVE-2022-33196HIGHCVSS 7.2EG 7.22023-02-16
Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via l…
- CVE-2022-3368HIGHCVSS 7.3EG 8.82022-10-17
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security versi…
- CVE-2022-33877HIGHCVSS 7.0EG 7.02023-06-13
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a lo…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →