CWE-277
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-277page 2 of 2
- CVE-2024-51448MEDIUMCVSS 6.7EG 6.72025-01-18
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-pri…
- CVE-2024-6605HIGHCVSS 8.8EG 8.82024-07-09
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
- CVE-2024-7143MEDIUMCVSS 6.7EG 6.72024-08-07
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method …
- CVE-2025-11554MEDIUMCVSS 6.3EG 6.32025-10-09
A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipul…
- CVE-2025-20008HIGHCVSS 7.7EG 7.72025-05-13
Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-20629MEDIUMCVSS 6.7EG 6.72025-05-13
Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-22448MEDIUMCVSS 6.1EG 6.12025-05-13
Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-24327MEDIUMCVSS 6.7EG 6.72025-11-11
Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated use…
- CVE-2025-29982MEDIUMCVSS 6.8EG 6.82025-04-02
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
- CVE-2025-31332MEDIUMCVSS 6.6EG 6.62025-04-08
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high i…
- CVE-2025-32092MEDIUMCVSS 6.7EG 6.72026-02-10
Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with …
- CVE-2025-32797HIGHCVSS 7.0EG 7.02025-06-16
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), al…
- CVE-2025-3473MEDIUMCVSS 6.7EG 6.72025-06-11
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
- CVE-2025-36104MEDIUMCVSS 6.5EG 6.52025-07-12
IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protocol.
- CVE-2025-37174HIGHCVSS 7.2EG 7.22026-01-13
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to …
- CVE-2025-56019MEDIUMCVSS 6.5EG 6.52025-10-02
An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is est…
- CVE-2025-58437HIGHCVSS 8.1EG 8.12025-09-06
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automati…
- CVE-2025-64185MEDIUMCVSS 6.9EG 0.02025-11-20
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
- CVE-2025-65111MEDIUMCVSS 5.3EG 5.32025-11-21
SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that…
- CVE-2025-9039MEDIUMCVSS 4.3EG 4.32025-08-14
We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the instances are in the same security group or if their security groups allow incomi…
- CVE-2026-20630MEDIUMCVSS 5.5EG 5.52026-02-11
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
- CVE-2026-30266HIGHCVSS 7.8EG 7.82026-04-20
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file
- CVE-2026-7891CRITICALCVSS 9.3EG 9.32026-05-07
The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration. The VerySecureApp allows anonymous users of the MyFirstModule with the anonymous user role to gain ac…
Map vulnerabilities like CWE-277 to your infrastructure
EchelonGraph correlates every CVE — across CWE-277 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →