CWE-276— Incorrect Default Permissions
1,613 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 22 of 33
- CVE-2023-42928HIGHCVSS 7.8EG 8.42024-02-21
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges.
- CVE-2023-42945MEDIUMCVSS 5.5EG 9.12024-02-21
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Bluetooth.
- CVE-2023-42953MEDIUMCVSS 5.5EG 5.52024-02-21
A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.
- CVE-2023-43081MEDIUMCVSS 4.0EG 4.02023-11-22
PowerProtect Agent for File System Version 19.14 and prior, contains an incorrect default permissions vulnerability in ddfscon component. A low Privileged local attacker could potentially exploit this vulnerability, leading to overwriting…
- CVE-2023-43496HIGHCVSS 8.8EG 8.82023-09-20
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with acc…
- CVE-2023-43629HIGHCVSS 7.8EG 7.82024-05-16
Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-43747MEDIUMCVSS 6.7EG 6.72024-08-14
Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-43902CRITICALCVSS 9.8EG 9.82023-11-14
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
- CVE-2023-43984HIGHCVSS 7.5EG 7.52023-11-07
Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
- CVE-2023-44157HIGHCVSS 7.8EG 3.32023-09-27
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979.
- CVE-2023-44194HIGHCVSS 8.4EG 8.42023-10-13
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to create a backdoor with root privileges. The issue is caused by improper directory permission…
- CVE-2023-45690MEDIUMCVSS 4.9EG 4.92023-10-16
Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's authentication to the OS to read sensitive files on the filesystem
- CVE-2023-45896HIGHCVSS 7.1EG 7.12024-08-28
ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution is configured to allow unprivileged mounts of removable media) and then leveraging…
- CVE-2023-45990HIGHCVSS 8.0EG 8.02023-10-25
Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.
- CVE-2023-46270LOWCVSS 3.3EG 3.32024-04-29
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.
- CVE-2023-4664HIGHCVSS 8.8EG 7.12023-09-15
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.
- CVE-2023-46743HIGHCVSS 7.3EG 7.32023-11-09
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments files in view or edit m…
- CVE-2023-46773CRITICALCVSS 9.8EG 9.82023-12-06
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2023-46870HIGHCVSS 7.3EG 7.32024-05-14
extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code e…
- CVE-2023-4706HIGHCVSS 7.3EG 7.32023-11-08
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.
- CVE-2023-47250HIGHCVSS 8.8EG 8.82023-11-22
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DI…
- CVE-2023-47335MEDIUMCVSS 6.5EG 6.52023-11-16
Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones.
- CVE-2023-47462CRITICALCVSS 9.8EG 9.82023-11-29
Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function.
- CVE-2023-48648CRITICALCVSS 9.8EG 9.82023-11-17
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folder…
- CVE-2023-48678MEDIUMCVSS 5.5EG 5.52024-02-27
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
- CVE-2023-49338HIGHCVSS 7.5EG 7.52024-02-28
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.
- CVE-2023-49721MEDIUMCVSS 6.7EG 6.72024-02-14
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
- CVE-2023-50236HIGHCVSS 7.8EG 7.82024-02-13
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in the installation path. An attacker with local access could exploit this vulnerabili…
- CVE-2023-5042HIGHCVSS 7.5EG 5.52023-09-20
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.
- CVE-2023-50612HIGHCVSS 7.8EG 7.82024-01-06
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.
- CVE-2023-50975HIGHCVSS 8.4EG 8.42024-02-21
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a …
- CVE-2023-52362HIGHCVSS 7.5EG 7.52024-02-18
Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.
- CVE-2023-52379HIGHCVSS 7.5EG 7.52024-02-18
Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-52545HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52717MEDIUMCVSS 5.3EG 5.32024-04-07
Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52954MEDIUMCVSS 4.4EG 4.42025-01-08
Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2023-5536MEDIUMCVSS 5.0EG 5.02023-12-12
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
- CVE-2023-5623HIGHCVSS 7.0EG 7.02023-10-26
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location
- CVE-2023-6273MEDIUMCVSS 5.3EG 5.32023-12-06
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-6302MEDIUMCVSS 4.7EG 4.72023-11-27
A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipulation leads to permission issues. The at…
- CVE-2023-6457MEDIUMCVSS 6.6EG 6.62024-01-16
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.
- CVE-2023-7235HIGHCVSS 8.4EG 8.42024-02-21
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries t…
- CVE-2024-0034HIGHCVSS 7.8EG 7.82024-02-16
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2024-0245MEDIUMCVSS 5.5EG 5.52025-03-20
A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permissions of the vulnerable app, potentially leading to the expos…
- CVE-2024-0259HIGHCVSS 7.3EG 7.32024-03-28
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with loc…
- CVE-2024-0770MEDIUMCVSS 4.4EG 4.42024-01-21
A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file iuclid6.exe of the component Desktop Installer. The manipulation leads to incor…
- CVE-2024-0833HIGHCVSS 7.8EG 7.82024-01-31
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower…
- CVE-2024-10183MEDIUMCVSS 5.2EG 0.02024-10-22
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.
- CVE-2024-10251HIGHCVSS 7.8EG 7.82024-12-11
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
- CVE-2024-10469MEDIUMCVSS 6.5EG 6.52024-10-28
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →