CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 28 of 34
- CVE-2024-52783MEDIUMCVSS 5.1EG 5.12025-01-15
Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modification of the configuration file.
- CVE-2024-52867HIGHCVSS 8.1EG 8.12024-11-17
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be re…
- CVE-2024-52926HIGHCVSS 6.5EG 7.32024-11-18
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
- CVE-2024-52946HIGHCVSS 8.8EG 8.82024-11-18
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment…
- CVE-2024-5321MEDIUMCVSS 6.1EG 6.12024-07-18
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
- CVE-2024-53351CRITICALCVSS 9.8EG 9.82025-03-21
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
- CVE-2024-53835HIGHCVSS 7.8EG 7.82025-01-03
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-53840HIGHCVSS 7.8EG 7.82025-01-03
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-53841HIGHCVSS 7.8EG 7.82025-01-03
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2024-53921LOWCVSS 2.8EG 2.82024-12-03
An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.
- CVE-2024-54131HIGHCVSS 7.3EG 7.32024-12-03
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11…
- CVE-2024-54564MEDIUMCVSS 6.5EG 6.52025-03-21
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file received from AirDrop may not have the quarantine flag applied.
- CVE-2024-5474MEDIUMCVSS 5.5EG 5.52024-10-11
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges durin…
- CVE-2024-54745CRITICALCVSS 9.8EG 9.82024-12-06
WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-54747CRITICALCVSS 9.8EG 9.82024-12-06
WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-54751CRITICALCVSS 9.8EG 9.82024-12-10
COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-55215CRITICALCVSS 9.8EG 9.82025-02-07
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
- CVE-2024-55225CRITICALCVSS 9.8EG 9.82025-01-09
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
- CVE-2024-55398MEDIUMCVSS 6.5EG 6.52025-08-06
4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
- CVE-2024-55930MEDIUMCVSS 6.7EG 6.72025-01-23
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
- CVE-2024-55950HIGHCVSS 8.6EG 8.62024-12-26
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential s…
- CVE-2024-55956CRITICALCVSS 9.8EG 9.8⚠ KEV2024-12-13
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autor…
- CVE-2024-55957HIGHCVSS 7.8EG 7.82025-01-22
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on…
- CVE-2024-55959CRITICALCVSS 9.1EG 9.12025-01-21
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
- CVE-2024-56440MEDIUMCVSS 6.2EG 6.22025-01-08
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2024-56447HIGHCVSS 7.8EG 7.82025-01-08
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-56525CRITICALCVSS 9.8EG 9.82025-02-24
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading …
- CVE-2024-57032CRITICALCVSS 9.8EG 9.82025-01-17
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.
- CVE-2024-57438MEDIUMCVSS 5.4EG 5.42025-01-29
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
- CVE-2024-57548CRITICALCVSS 9.1EG 9.12025-01-27
CMSimple 5.16 allows the user to edit log.php file via print page.
- CVE-2024-57604CRITICALCVSS 9.8EG 9.82025-02-12
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
- CVE-2024-57684CRITICALCVSS 9.8EG 9.82025-01-16
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
- CVE-2024-58044HIGHCVSS 8.4EG 8.42025-03-04
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-58046MEDIUMCVSS 6.2EG 6.22025-03-04
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-58047MEDIUMCVSS 5.0EG 5.02025-03-04
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-58049MEDIUMCVSS 5.0EG 5.02025-03-04
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-58050MEDIUMCVSS 6.2EG 6.22025-03-04
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-58356LOWCVSS 2.3EG 2.32026-07-18
SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a…
- CVE-2024-5967LOWCVSS 2.7EG 2.72024-06-18
A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permis…
- CVE-2024-6122MEDIUMCVSS 5.5EG 5.52024-07-22
An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It al…
- CVE-2024-6148HIGHCVSS 8.8EG 8.82024-07-10
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
- CVE-2024-6238HIGHCVSS 7.4EG 7.42024-06-25
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.
- CVE-2024-6325MEDIUMCVSS 6.5EG 6.52024-07-16
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-…
- CVE-2024-6326MEDIUMCVSS 5.5EG 5.52024-07-16
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes priva…
- CVE-2024-6476MEDIUMCVSS 4.2EG 4.22024-11-26
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for…
- CVE-2024-6640MEDIUMCVSS 6.3EG 6.32024-08-12
In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo Request packet after a Neighbor Solicitation (NS) can trigger an Echo Reply. The packet has to come…
- CVE-2024-6974HIGHCVSS 8.8EG 8.82024-07-31
Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.
- CVE-2024-7525CRITICALCVSS 8.1EG 9.12024-08-06
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firef…
- CVE-2024-7587HIGHCVSS 7.8EG 7.82024-10-22
Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prio…
- CVE-2024-8037MEDIUMCVSS 6.5EG 6.52024-10-02
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →