CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 25 of 34
- CVE-2024-27148HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27149HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27150HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27151HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affe…
- CVE-2024-27152HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27153HIGHCVSS 7.4EG 7.42024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27155HIGHCVSS 7.7EG 7.72024-06-14
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affe…
- CVE-2024-27166HIGHCVSS 7.4EG 7.42024-06-14
Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27167HIGHCVSS 7.4EG 7.42024-06-14
Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the refe…
- CVE-2024-27171HIGHCVSS 7.4EG 7.42024-06-14
A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27180MEDIUMCVSS 6.7EG 6.72024-06-14
An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.
- CVE-2024-27264HIGHCVSS 7.4EG 7.42024-05-22
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-For…
- CVE-2024-27461MEDIUMCVSS 5.6EG 5.62024-08-14
Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-27674HIGHCVSS 7.8EG 7.82024-04-03
Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivileged user can escalate to SYSTEM by replacing the MacroService.exe binary.
- CVE-2024-27888HIGHCVSS 5.5EG 7.12024-07-29
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sonoma 14.4. An app may be able to modify protected parts of the file system.
- CVE-2024-28056CRITICALCVSS 9.8EG 9.82024-04-15
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Ef…
- CVE-2024-28058HIGHCVSS 7.5EG 7.52024-11-18
In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive d…
- CVE-2024-2819MEDIUMCVSS 5.1EG 5.12024-07-02
Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.
- CVE-2024-2859MEDIUMCVSS 6.8EG 6.82024-04-27
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.
- CVE-2024-28862MEDIUMCVSS 5.3EG 5.32024-03-16
The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch m…
- CVE-2024-28954MEDIUMCVSS 6.7EG 6.72025-05-13
Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-29083MEDIUMCVSS 6.7EG 6.72024-11-13
Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-29962MEDIUMCVSS 5.5EG 5.52024-04-19
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.
- CVE-2024-29967MEDIUMCVSS 4.4EG 4.42024-04-19
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo …
- CVE-2024-30204LOWCVSS 2.8EG 2.82024-03-25
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
- CVE-2024-30415CRITICALCVSS 9.1EG 9.12024-04-07
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-30977HIGHCVSS 7.8EG 7.82024-04-05
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.
- CVE-2024-31312MEDIUMCVSS 5.5EG 5.52024-07-09
In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not ne…
- CVE-2024-31442HIGHCVSS 8.8EG 8.82024-04-08
Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users, including admin commands. This allows users to receive products for free and delete/crea…
- CVE-2024-32368HIGHCVSS 7.3EG 7.32024-04-22
Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via the Bluetooth Low Energy (BLE) component.
- CVE-2024-32861HIGHCVSS 7.8EG 7.82024-07-16
Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.
- CVE-2024-32942MEDIUMCVSS 6.7EG 6.72025-02-12
Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-32978MEDIUMCVSS 6.6EG 6.62024-05-27
Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecure file permissions has been identified in the Kaminari pagination library for Ruby on Rails, concerning insecure file …
- CVE-2024-34011MEDIUMCVSS 6.8EG 6.82024-04-29
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758.
- CVE-2024-34012MEDIUMCVSS 4.4EG 4.42024-06-14
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.
- CVE-2024-34018MEDIUMCVSS 5.5EG 5.52024-08-29
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.
- CVE-2024-34221HIGHCVSS 8.8EG 8.82024-05-14
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
- CVE-2024-34223MEDIUMCVSS 4.3EG 4.32024-05-14
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
- CVE-2024-34455HIGHCVSS 7.5EG 7.52024-05-03
Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.
- CVE-2024-34474HIGHCVSS 7.8EG 7.82024-05-05
Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.
- CVE-2024-34616MEDIUMCVSS 5.1EG 5.12024-08-07
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.
- CVE-2024-34617MEDIUMCVSS 4.0EG 4.02024-08-07
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
- CVE-2024-34648MEDIUMCVSS 5.1EG 5.12024-09-04
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
- CVE-2024-34661MEDIUMCVSS 4.3EG 4.32024-09-04
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.
- CVE-2024-34679MEDIUMCVSS 4.0EG 4.02024-11-06
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
- CVE-2024-34730HIGHCVSS 7.8EG 7.82025-01-21
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
- CVE-2024-35139MEDIUMCVSS 6.2EG 6.22024-06-28
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
- CVE-2024-35201MEDIUMCVSS 6.7EG 6.72024-11-13
Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access.
- CVE-2024-35287MEDIUMCVSS 6.7EG 6.72024-10-21
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution …
- CVE-2024-36063HIGHCVSS 7.5EG 7.52024-11-07
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activit…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →