CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 32 of 34
- CVE-2025-48950HIGHCVSS 8.8EG 8.82025-06-03
MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/bin,/usr/bin`, etc. Therefore, attackers can exploit some f…
- CVE-2025-48959MEDIUMCVSS 6.7EG 6.72025-06-04
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40077.
- CVE-2025-49006HIGHCVSS 8.2EG 8.22025-06-09
Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6, Wasp authentication has a vulnerability in the OAuth authentication implementation (affecting only Keycloak with a spec…
- CVE-2025-49082LOWCVSS 2.7EG 2.72025-07-31
CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those perm…
- CVE-2025-49084CRITICALCVSS 9.1EG 9.12025-07-31
CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, …
- CVE-2025-49144HIGHCVSS 7.3EG 7.32025-06-23
Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insec…
- CVE-2025-49842LOWCVSS 1.0EG 1.02025-06-17
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without specifying a user. By default, Docker containe…
- CVE-2025-49843LOWCVSS 2.7EG 2.72025-06-17
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_headers function in the conda-smithy repository creates files wi…
- CVE-2025-5199HIGHCVSS 7.3EG 7.32025-07-12
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system sta…
- CVE-2025-52361HIGHCVSS 7.8EG 7.82025-08-01
Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated low-privilege user to execute arbitrary commands with root privilege via editing this script…
- CVE-2025-5255MEDIUMCVSS 4.8EG 4.82025-06-20
The Phoenix Code's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-environment-variables" and "com.apple.security.cs.disable-library-validation" allows for Dynamic Library (Dylib) inject…
- CVE-2025-52900MEDIUMCVSS 5.5EG 5.52025-06-26
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never exp…
- CVE-2025-52991LOWCVSS 3.2EG 3.22025-06-27
The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing conten…
- CVE-2025-53398HIGHCVSS 7.8EG 7.82025-12-17
The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
- CVE-2025-53811MEDIUMCVSS 4.8EG 4.82025-08-26
The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency, Consent, and Control) permissions. A…
- CVE-2025-53813MEDIUMCVSS 4.8EG 4.82025-08-26
The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Nozbe TCC (Transparency, Consent, and Control) permissions. Acquire…
- CVE-2025-53919HIGHCVSS 7.8EG 7.82025-12-17
An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local…
- CVE-2025-53945HIGHCVSS 7.0EG 7.02025-07-18
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. V…
- CVE-2025-53947HIGHCVSS 7.7EG 7.72025-09-18
A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data folder is created with very weak privileges, allowing any user logged into the W…
- CVE-2025-54059MEDIUMCVSS 4.4EG 4.42025-07-18
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unpriv…
- CVE-2025-54085LOWCVSS 3.8EG 3.82025-07-31
CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those perm…
- CVE-2025-54086LOWCVSS 3.3EG 3.32025-10-02
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low…
- CVE-2025-54530HIGHCVSS 7.5EG 7.52025-07-28
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
- CVE-2025-54866MEDIUMCVSS 5.5EG 5.52025-11-21
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "C:\Program Files (x86)\ossec-agent\authd.pass" exposes the password to all "Authenticated …
- CVE-2025-54990MEDIUMCVSS 5.3EG 5.32025-11-18
XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTo…
- CVE-2025-55111MEDIUMCVSS 5.5EG 5.52025-09-16
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected…
- CVE-2025-55132MEDIUMCVSS 5.3EG 5.32026-01-20
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permiss…
- CVE-2025-57625HIGHCVSS 8.8EG 8.82025-09-16
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM by replac…
- CVE-2025-57846HIGHCVSS 7.8EG 7.82025-08-27
Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacker may replace a service executable on the system where the product is running, potent…
- CVE-2025-57847MEDIUMCVSS 6.4EG 6.42026-04-08
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an at…
- CVE-2025-57848MEDIUMCVSS 6.4EG 6.42025-10-23
A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attack…
- CVE-2025-57849MEDIUMCVSS 6.4EG 6.42026-03-13
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands…
- CVE-2025-57850MEDIUMCVSS 6.4EG 6.42025-12-02
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can …
- CVE-2025-57851MEDIUMCVSS 6.7EG 6.72026-04-08
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an att…
- CVE-2025-57852MEDIUMCVSS 6.4EG 6.42025-09-30
A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can ex…
- CVE-2025-57853MEDIUMCVSS 6.4EG 6.42026-04-08
A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute …
- CVE-2025-57854MEDIUMCVSS 6.4EG 6.42026-04-08
A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attack…
- CVE-2025-58097HIGHCVSS 7.8EG 7.82025-11-21
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.
- CVE-2025-58712MEDIUMCVSS 6.4EG 6.42025-10-22
A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute co…
- CVE-2025-58713MEDIUMCVSS 6.4EG 6.42026-04-08
A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an att…
- CVE-2025-59030HIGHCVSS 7.5EG 7.52025-12-09
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
- CVE-2025-59485LOWCVSS 3.3EG 3.32025-11-25
Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerability is exploited, an arbitrary file could be placed in the specific folder by a user who can log in to the system where …
- CVE-2025-5963MEDIUMCVSS 4.8EG 4.82025-06-20
The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-environment-variables" and "com.apple.security.cs.disable-library-validation" allows for Dynamic Library (Dylib) injection. …
- CVE-2025-60262CRITICALCVSS 9.8EG 9.82026-01-06
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP proto…
- CVE-2025-61035HIGHCVSS 7.7EG 7.72025-10-22
The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik file, which is created with mode 0777 and 0775 respectively, exposing secrets to other local users. Add…
- CVE-2025-61229HIGHCVSS 7.8EG 7.82025-12-01
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
- CVE-2025-61667HIGHCVSS 7.0EG 7.02025-11-12
The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due to insufficient permissions being set on the `opt/datadog-age…
- CVE-2025-6179CRITICALCVSS 9.8EG 9.82025-06-16
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vuln…
- CVE-2025-62577HIGHCVSS 8.8EG 8.82025-10-20
ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS command…
- CVE-2025-6264MEDIUMCVSS 5.5EG 5.52025-06-20
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows f…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →