CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 27 of 34
- CVE-2024-46054CRITICALCVSS 9.8EG 9.82024-11-27
OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.
- CVE-2024-46462HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vuln…
- CVE-2024-46463HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulner…
- CVE-2024-46464HIGHCVSS 7.8EG 7.82025-01-09
In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer unavailable or to execute programs with an elevation of privilege.
- CVE-2024-46465HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulner…
- CVE-2024-46466HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configura…
- CVE-2024-46467HIGHCVSS 7.8EG 7.82024-11-15
By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this …
- CVE-2024-46505CRITICALCVSS 9.1EG 9.12025-01-09
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
- CVE-2024-46544MEDIUMCVSS 5.9EG 5.92024-09-23
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affe…
- CVE-2024-46624HIGHCVSS 8.8EG 8.82024-12-03
An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.
- CVE-2024-46695MEDIUMCVSS 4.4EG 4.42024-09-13
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on f…
- CVE-2024-4679HIGHCVSS 7.8EG 7.82024-07-02
Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issu…
- CVE-2024-46894MEDIUMCVSS 6.3EG 6.32024-11-12
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated rem…
- CVE-2024-46916HIGHCVSS 8.1EG 8.12025-08-29
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remo…
- CVE-2024-47012HIGHCVSS 7.8EG 7.82024-10-25
In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2024-47013HIGHCVSS 7.8EG 7.82024-10-25
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2024-47014HIGHCVSS 8.8EG 8.82024-10-25
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.
- CVE-2024-47016HIGHCVSS 7.8EG 7.82024-10-25
there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-47240MEDIUMCVSS 5.5EG 5.52024-10-18
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potentially exploit this vulnerability to gain write access to unauth…
- CVE-2024-47550MEDIUMCVSS 6.7EG 6.72025-05-13
Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-47593MEDIUMCVSS 4.3EG 4.32024-11-12
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server i…
- CVE-2024-4763HIGHCVSS 7.8EG 7.82024-08-16
An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.
- CVE-2024-47825MEDIUMCVSS 4.0EG 4.02024-10-21
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than `/32` may be ignored if th…
- CVE-2024-48292HIGHCVSS 8.8EG 8.82024-11-18
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.
- CVE-2024-48293MEDIUMCVSS 6.5EG 6.52024-11-18
Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.
- CVE-2024-48533MEDIUMCVSS 5.3EG 5.32024-11-20
A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts.
- CVE-2024-48572MEDIUMCVSS 5.3EG 5.32024-10-29
A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs due to insufficiently validated user input being processed a…
- CVE-2024-48822HIGHCVSS 8.8EG 8.82024-10-14
Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.
- CVE-2024-48823CRITICALCVSS 9.8EG 9.82024-10-14
Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page.
- CVE-2024-49202HIGHCVSS 7.6EG 7.62024-12-18
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.
- CVE-2024-49389HIGHCVSS 7.8EG 7.82024-10-17
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
- CVE-2024-49504HIGHCVSS 7.0EG 7.02024-11-13
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
- CVE-2024-49724HIGHCVSS 7.0EG 7.02025-01-21
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privi…
- CVE-2024-49732HIGHCVSS 7.8EG 7.82025-01-21
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution…
- CVE-2024-49735HIGHCVSS 7.8EG 7.82025-01-21
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2024-49736HIGHCVSS 5.5EG 7.82025-01-21
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User …
- CVE-2024-49737HIGHCVSS 7.8EG 7.82025-01-21
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local escalation of privilege with no additional…
- CVE-2024-49742HIGHCVSS 7.8EG 7.82025-01-21
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional…
- CVE-2024-49744HIGHCVSS 7.8EG 7.82025-01-21
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution p…
- CVE-2024-50590HIGHCVSS 7.8EG 7.82024-11-08
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory …
- CVE-2024-50657MEDIUMCVSS 6.8EG 6.82024-11-22
An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method
- CVE-2024-51051CRITICALCVSS 9.8EG 9.82024-11-18
AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
- CVE-2024-51162CRITICALCVSS 8.8EG 9.82024-11-20
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole …
- CVE-2024-51378CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-29
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secM…
- CVE-2024-51440HIGHCVSS 7.8EG 7.82025-02-12
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
- CVE-2024-51567CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-29
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is …
- CVE-2024-51764MEDIUMCVSS 5.5EG 5.52024-11-15
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
- CVE-2024-51765MEDIUMCVSS 5.5EG 5.52024-11-15
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
- CVE-2024-52323HIGHCVSS 8.1EG 8.12024-11-27
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.
- CVE-2024-52551HIGHCVSS 8.0EG 8.02024-11-13
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to res…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →