CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 19 of 34
- CVE-2022-42130MEDIUMCVSS 4.3EG 4.32022-11-15
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remot…
- CVE-2022-42150CRITICALCVSS 10.0EG 10.02023-10-19
TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.
- CVE-2022-42446MEDIUMCVSS 6.5EG 6.52022-12-12
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.
- CVE-2022-42464HIGHCVSS 6.7EG 7.82022-10-14
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the d…
- CVE-2022-42718HIGHCVSS 7.8EG 7.82022-12-01
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-43574HIGHCVSS 7.5EG 7.52022-11-03
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."
- CVE-2022-43701HIGHCVSS 7.8EG 7.82023-07-27
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
- CVE-2022-43702HIGHCVSS 7.8EG 7.82023-07-27
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
- CVE-2022-44548MEDIUMCVSS 4.3EG 4.32022-11-09
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.
- CVE-2022-44554HIGHCVSS 7.5EG 7.52022-11-09
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
- CVE-2022-44557HIGHCVSS 7.5EG 7.52022-11-09
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-44561HIGHCVSS 7.5EG 7.52022-11-09
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
- CVE-2022-44929CRITICALCVSS 9.8EG 9.82022-12-02
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
- CVE-2022-45097HIGHCVSS 6.3EG 8.82023-02-01
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure. …
- CVE-2022-45099HIGHCVSS 7.8EG 7.82023-02-01
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
- CVE-2022-45118MEDIUMCVSS 6.2EG 6.22022-12-08
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information …
- CVE-2022-45153HIGHCVSS 7.0EG 7.82023-02-15
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to r…
- CVE-2022-45452HIGHCVSS 7.8EG 7.82023-05-18
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.
- CVE-2022-45454HIGHCVSS 7.5EG 7.52023-02-13
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984.
- CVE-2022-45459HIGHCVSS 7.5EG 7.52023-05-18
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.
- CVE-2022-45552HIGHCVSS 7.5EG 7.52023-03-03
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.
- CVE-2022-45562HIGHCVSS 8.8EG 8.82022-12-02
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands i…
- CVE-2022-4568HIGHCVSS 7.0EG 7.02023-05-01
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
- CVE-2022-4569HIGHCVSS 7.8EG 7.82023-06-05
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
- CVE-2022-4575MEDIUMCVSS 6.7EG 6.72023-10-30
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
- CVE-2022-45793MEDIUMCVSS 5.5EG 5.52024-01-10
Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.
- CVE-2022-45853MEDIUMCVSS 6.7EG 6.72023-05-30
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some sy…
- CVE-2022-45924HIGHCVSS 8.1EG 8.12023-01-18
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem.
- CVE-2022-46382HIGHCVSS 8.8EG 8.82022-12-06
RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. After signing into Digital Rebar, users are issued authentication tokens tied to their account…
- CVE-2022-46761HIGHCVSS 7.5EG 7.52023-01-06
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
- CVE-2022-46774MEDIUMCVSS 5.4EG 6.52023-03-15
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.
- CVE-2022-47040HIGHCVSS 7.8EG 7.82023-01-26
An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after placing a crafted file in the /tmp directory and sending crafted packets through port 80.
- CVE-2022-47450MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
- CVE-2022-47551MEDIUMCVSS 6.5EG 6.52022-12-20
Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatib…
- CVE-2022-48199HIGHCVSS 8.8EG 8.82023-01-26
SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitr…
- CVE-2022-48360HIGHCVSS 7.5EG 7.52023-03-27
The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2022-48685HIGHCVSS 7.7EG 7.72024-04-27
An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.
- CVE-2022-4964MEDIUMCVSS 5.5EG 5.52024-01-24
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
- CVE-2023-0181HIGHCVSS 7.1EG 7.12023-04-01
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.
- CVE-2023-1229MEDIUMCVSS 4.3EG 4.32023-03-07
Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-1693HIGHCVSS 7.5EG 7.52023-05-20
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-1809HIGHCVSS 7.5EG 7.52023-05-02
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
- CVE-2023-1907HIGHCVSS 8.0EG 8.02025-01-09
A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.
- CVE-2023-20043MEDIUMCVSS 6.7EG 6.72023-01-20
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the scr…
- CVE-2023-20178HIGHCVSS 7.8EG 7.82023-06-28
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to …
- CVE-2023-21104MEDIUMCVSS 5.5EG 5.52023-05-15
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions…
- CVE-2023-21107HIGHCVSS 7.8EG 7.82023-05-15
In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not nee…
- CVE-2023-21121HIGHCVSS 7.8EG 7.82023-06-15
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution …
- CVE-2023-21126HIGHCVSS 7.8EG 7.82023-06-15
In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges nee…
- CVE-2023-21128HIGHCVSS 7.8EG 7.82023-06-15
In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. …
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →