CWE-276— Incorrect Default Permissions
1,613 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 26 of 33
- CVE-2024-43089HIGHCVSS 7.8EG 7.82024-11-13
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
- CVE-2024-43114HIGHCVSS 7.5EG 7.52024-08-06
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
- CVE-2024-43166CRITICALCVSS 9.8EG 9.82025-09-03
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
- CVE-2024-43176MEDIUMCVSS 5.4EG 5.42025-01-09
IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.
- CVE-2024-43430MEDIUMCVSS 5.3EG 5.32024-11-11
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
- CVE-2024-43765HIGHCVSS 7.8EG 7.82025-01-21
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploita…
- CVE-2024-43769HIGHCVSS 7.8EG 7.82025-01-03
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional e…
- CVE-2024-43791HIGHCVSS 7.8EG 7.82024-08-23
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was…
- CVE-2024-44100HIGHCVSS 7.5EG 7.52024-10-25
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
- CVE-2024-44135MEDIUMCVSS 5.5EG 5.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. An app may be able to access protected files within an App Sandbox container.
- CVE-2024-44151MEDIUMCVSS 5.5EG 5.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify protected parts of the file system.
- CVE-2024-44224HIGHCVSS 7.8EG 7.82024-12-12
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able to gain root privileges.
- CVE-2024-44228HIGHCVSS 7.5EG 7.52024-10-28
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
- CVE-2024-44760HIGHCVSS 7.5EG 9.12024-08-28
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
- CVE-2024-44786HIGHCVSS 7.5EG 7.52024-11-22
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.
- CVE-2024-45067HIGHCVSS 8.2EG 8.22025-05-14
Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-45494CRITICALCVSS 9.8EG 9.82024-12-10
An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented thro…
- CVE-2024-45690HIGHCVSS 7.5EG 7.52024-11-20
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
- CVE-2024-45819MEDIUMCVSS 5.5EG 5.52024-12-19
PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly…
- CVE-2024-46054CRITICALCVSS 9.8EG 9.82024-11-27
OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.
- CVE-2024-46462HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vuln…
- CVE-2024-46463HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulner…
- CVE-2024-46464HIGHCVSS 7.8EG 7.82025-01-09
In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer unavailable or to execute programs with an elevation of privilege.
- CVE-2024-46465HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulner…
- CVE-2024-46466HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configura…
- CVE-2024-46467HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this …
- CVE-2024-46505CRITICALCVSS 9.1EG 9.12025-01-09
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
- CVE-2024-46544MEDIUMCVSS 5.9EG 5.92024-09-23
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affe…
- CVE-2024-46624HIGHCVSS 8.8EG 8.82024-12-03
An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.
- CVE-2024-46695MEDIUMCVSS 4.4EG 4.42024-09-13
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on f…
- CVE-2024-4679HIGHCVSS 7.8EG 7.82024-07-02
Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issu…
- CVE-2024-46894MEDIUMCVSS 6.3EG 6.32024-11-12
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated rem…
- CVE-2024-46916HIGHCVSS 8.1EG 8.12025-08-29
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remo…
- CVE-2024-47012HIGHCVSS 7.8EG 7.82024-10-25
In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2024-47013HIGHCVSS 7.8EG 7.82024-10-25
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2024-47014HIGHCVSS 8.8EG 8.82024-10-25
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.
- CVE-2024-47016HIGHCVSS 7.8EG 7.82024-10-25
there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-47240MEDIUMCVSS 5.5EG 5.52024-10-18
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potentially exploit this vulnerability to gain write access to unauth…
- CVE-2024-47550MEDIUMCVSS 6.7EG 6.72025-05-13
Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-47593MEDIUMCVSS 4.3EG 4.32024-11-12
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server i…
- CVE-2024-4763HIGHCVSS 7.8EG 7.82024-08-16
An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.
- CVE-2024-47825MEDIUMCVSS 4.0EG 4.02024-10-21
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than `/32` may be ignored if th…
- CVE-2024-48292HIGHCVSS 8.8EG 8.82024-11-18
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.
- CVE-2024-48293MEDIUMCVSS 6.5EG 6.52024-11-18
Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.
- CVE-2024-48533MEDIUMCVSS 5.3EG 5.32024-11-20
A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts.
- CVE-2024-48572MEDIUMCVSS 5.3EG 5.32024-10-29
A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs due to insufficiently validated user input being processed a…
- CVE-2024-48822HIGHCVSS 8.8EG 8.82024-10-14
Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.
- CVE-2024-48823CRITICALCVSS 9.8EG 9.82024-10-14
Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page.
- CVE-2024-49202HIGHCVSS 7.6EG 7.62024-12-18
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.
- CVE-2024-49389HIGHCVSS 7.8EG 7.82024-10-17
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →