CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 33 of 34
- CVE-2025-62661MEDIUMCVSS 6.9EG 6.92025-10-21
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mediawiki - T…
- CVE-2025-62668MEDIUMCVSS 6.9EG 6.92025-10-18
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.
- CVE-2025-64436MEDIUMCVSS 5.3EG 5.32025-11-07
KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration …
- CVE-2025-64723MEDIUMCVSS 4.4EG 4.42025-12-18
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows…
- CVE-2025-64724HIGHCVSS 7.3EG 7.32025-12-18
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files …
- CVE-2025-67230HIGHCVSS 7.1EG 7.12026-01-23
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke external protocol handlers without sufficient validation.
- CVE-2025-67813MEDIUMCVSS 5.3EG 5.32026-01-12
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication
- CVE-2025-69604HIGHCVSS 7.8EG 7.82026-01-29
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS p…
- CVE-2025-7024HIGHCVSS 7.3EG 7.32026-04-03
Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a cr…
- CVE-2025-7195MEDIUMCVSS 6.4EG 6.42025-08-07
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pas…
- CVE-2025-7672MEDIUMCVSS 4.3EG 4.32025-07-15
The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.
- CVE-2025-8031CRITICALCVSS 9.8EG 9.82025-07-22
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141…
- CVE-2025-8069HIGHCVSS 7.8EG 7.82025-07-23
During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin us…
- CVE-2025-8098HIGHCVSS 7.8EG 7.82025-08-18
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.
- CVE-2025-8421MEDIUMCVSS 6.6EG 6.62025-11-12
An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.
- CVE-2025-8432HIGHCVSS 8.4EG 8.42025-10-27
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, …
- CVE-2025-8485HIGHCVSS 7.3EG 7.32025-11-12
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.
- CVE-2025-8672HIGHCVSS 7.8EG 7.82025-08-11
MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter wi…
- CVE-2025-8766MEDIUMCVSS 6.4EG 6.42026-03-13
A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attack…
- CVE-2025-9190MEDIUMCVSS 4.8EG 4.82025-08-26
The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Cursor TCC (Transparency, Consent, and Control) permissions. Acquire…
- CVE-2026-0432HIGHCVSS 8.5EG 8.52026-05-15
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
- CVE-2026-0539HIGHCVSS 8.5EG 8.52026-04-22
Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting the service binary with arbitrary contents. This service binary is automatically launched…
- CVE-2026-0705MEDIUMCVSS 6.7EG 6.72026-01-27
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.4.25342.354.
- CVE-2026-0748MEDIUMCVSS 4.3EG 4.32026-03-26
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its a…
- CVE-2026-11931MEDIUMCVSS 5.5EG 5.52026-06-15
Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permi…
- CVE-2026-12602HIGHCVSS 8.8EG 8.82026-06-22
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other …
- CVE-2026-12823LOWCVSS 3.3EG 3.32026-06-22
A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a…
- CVE-2026-16246HIGHCVSS 7.3EG 7.32026-07-20
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. …
- CVE-2026-16247HIGHCVSS 7.3EG 7.32026-07-20
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control ins…
- CVE-2026-17497HIGHCVSS 8.3EG 8.32026-07-26
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invo…
- CVE-2026-2026MEDIUMCVSS 6.1EG 6.12026-02-13
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.
- CVE-2026-20718MEDIUMCVSS 5.4EG 5.42026-05-12
Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user c…
- CVE-2026-21013MEDIUMCVSS 5.5EG 5.52026-04-13
Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.
- CVE-2026-21015MEDIUMCVSS 5.5EG 5.52026-05-13
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
- CVE-2026-21423MEDIUMCVSS 6.7EG 6.72026-03-04
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, l…
- CVE-2026-21765HIGHCVSS 8.8EG 8.82026-04-02
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.
- CVE-2026-23703HIGHCVSS 7.8EG 7.82026-02-26
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.
- CVE-2026-24063HIGHCVSS 8.2EG 8.22026-03-18
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When…
- CVE-2026-24413MEDIUMCVSS 5.5EG 5.52026-01-29
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This res…
- CVE-2026-24414MEDIUMCVSS 5.5EG 5.52026-01-29
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificat…
- CVE-2026-24780HIGHCVSS 8.8EG 8.82026-01-29
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both mai…
- CVE-2026-25203HIGHCVSS 7.8EG 7.82026-04-10
Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.
- CVE-2026-25931HIGHCVSS 7.8EG 7.82026-02-09
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value …
- CVE-2026-26034HIGHCVSS 7.8EG 7.82026-03-05
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load …
- CVE-2026-26131HIGHCVSS 7.8EG 7.82026-03-10
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
- CVE-2026-27653MEDIUMCVSS 6.7EG 6.72026-02-27
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
- CVE-2026-27680MEDIUMCVSS 4.3EG 4.32026-05-14
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks …
- CVE-2026-28267MEDIUMCVSS 5.5EG 5.52026-03-10
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.
- CVE-2026-28717MEDIUMCVSS 5.0EG 5.02026-03-06
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
- CVE-2026-28727HIGHCVSS 7.8EG 7.82026-03-06
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image …
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →