CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 29 of 34
- CVE-2024-8496HIGHCVSS 7.8EG 7.82024-12-11
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
- CVE-2024-8533HIGHCVSS 8.8EG 8.82024-09-12
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
- CVE-2024-9167HIGHCVSS 7.8EG 7.82024-10-08
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
- CVE-2024-9191HIGHCVSS 7.1EG 7.12024-11-01
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless log…
- CVE-2024-9845HIGHCVSS 7.8EG 7.82024-12-11
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
- CVE-2024-9858HIGHCVSS 7.8EG 7.82024-10-16
There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" …
- CVE-2024-9947HIGHCVSS 8.1EG 8.12024-10-23
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it pos…
- CVE-2025-0014HIGHCVSS 7.3EG 7.32025-04-02
Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2025-0542HIGHCVSS 7.8EG 7.82025-01-25
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected instal…
- CVE-2025-0543HIGHCVSS 7.8EG 7.82025-01-25
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrar…
- CVE-2025-0797LOWCVSS 3.3EG 3.32025-01-29
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file /var/Microworld/ of the component Quarantine Handler. The manipulation leads …
- CVE-2025-0886HIGHCVSS 7.8EG 7.82025-07-17
An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges.
- CVE-2025-10231HIGHCVSS 7.0EG 7.02025-09-10
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.
- CVE-2025-10314HIGHCVSS 8.8EG 8.82026-02-05
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing service executable files…
- CVE-2025-10918HIGHCVSS 7.1EG 7.12025-11-11
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
- CVE-2025-11535HIGHCVSS 8.8EG 8.82025-10-08
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
- CVE-2025-11567HIGHCVSS 7.3EG 7.32025-11-12
CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.
- CVE-2025-11575HIGHCVSS 7.8EG 7.82025-10-23
Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.
- CVE-2025-12100HIGHCVSS 7.8EG 7.82025-10-23
Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.
- CVE-2025-12792LOWCVSS 3.2EG 3.22025-11-18
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and…
- CVE-2025-13025HIGHCVSS 7.5EG 7.52025-11-11
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
- CVE-2025-13130HIGHCVSS 7.8EG 7.82025-11-13
A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Service. Such manipulation leads to incorrect default permissions.…
- CVE-2025-13131HIGHCVSS 7.8EG 7.82025-11-13
A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permission…
- CVE-2025-13155HIGHCVSS 7.8EG 7.82025-12-10
An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.
- CVE-2025-13193MEDIUMCVSS 5.5EG 5.52025-11-17
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vul…
- CVE-2025-13905HIGHCVSS 7.0EG 7.02026-01-29
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal …
- CVE-2025-15333MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an information disclosure vulnerability in Threat Response.
- CVE-2025-15334MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an information disclosure vulnerability in Threat Response.
- CVE-2025-15335MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an information disclosure vulnerability in Threat Response.
- CVE-2025-15336MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Performance.
- CVE-2025-15337MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Patch.
- CVE-2025-15338MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
- CVE-2025-15339MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Discover.
- CVE-2025-15340MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Comply.
- CVE-2025-15341MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
- CVE-2025-15343MEDIUMCVSS 6.5EG 6.52026-02-05
Tanium addressed an incorrect default permissions vulnerability in Enforce.
- CVE-2025-15523MEDIUMCVSS 4.8EG 4.82026-01-22
MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interprete…
- CVE-2025-15615MEDIUMCVSS 5.8EG 5.82026-03-27
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending exces…
- CVE-2025-15642MEDIUMCVSS 6.8EG 6.82026-06-17
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DAC…
- CVE-2025-1699LOWCVSS 2.8EG 2.82025-06-11
An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.
- CVE-2025-1789HIGHCVSS 7.8EG 7.82026-02-24
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
- CVE-2025-20023MEDIUMCVSS 6.7EG 6.72025-08-12
Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-20087MEDIUMCVSS 6.7EG 6.72025-08-12
Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-20095MEDIUMCVSS 6.7EG 6.72025-05-13
Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-20156CRITICALCVSS 9.9EG 9.92025-01-22
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authoriz…
- CVE-2025-20910MEDIUMCVSS 6.2EG 6.22025-03-06
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
- CVE-2025-20984MEDIUMCVSS 6.8EG 6.82025-06-04
Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.
- CVE-2025-21106MEDIUMCVSS 5.5EG 5.52025-02-20
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the syst…
- CVE-2025-21532HIGHCVSS 7.8EG 7.82025-01-21
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the inf…
- CVE-2025-22425MEDIUMCVSS 5.1EG 5.12025-09-04
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for expl…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →