CWE-281— Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.— MITRE CWE catalog
358 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-281page 4 of 8
- CVE-2022-31096MEDIUMCVSS 5.7EG 5.72022-06-27
Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does not adhere to the email domain restriction of an invite lin…
- CVE-2022-31237LOWCVSS 3.3EG 3.32022-08-22
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to …
- CVE-2022-31262HIGHCVSS 7.8EG 7.82022-08-17
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service execu…
- CVE-2022-31608HIGHCVSS 7.8EG 7.82022-11-19
NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabilities can impact protected D-Bus endpoints, which may lead to code execution, denial of service, esc…
- CVE-2022-31755MEDIUMCVSS 5.5EG 5.52022-06-13
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-32969MEDIUMCVSS 5.9EG 5.92022-06-29
MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session featur…
- CVE-2022-36062HIGHCVSS 7.6EG 7.62022-09-22
Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is…
- CVE-2022-36102MEDIUMCVSS 6.3EG 6.32022-09-12
Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are…
- CVE-2022-38473HIGHCVSS 8.8EG 8.82022-12-22
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR <…
- CVE-2022-38577HIGHCVSS 8.8EG 8.82022-09-19
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
- CVE-2022-4139HIGHCVSS 7.8EG 7.82023-01-27
An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on th…
- CVE-2022-41708MEDIUMCVSS 4.3EG 4.32022-10-19
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.
- CVE-2022-41963LOWCVSS 2.7EG 2.72022-12-16
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds …
- CVE-2022-42260HIGHCVSS 7.8EG 7.82022-12-30
NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escala…
- CVE-2022-4326MEDIUMCVSS 5.5EG 6.02022-12-16
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly a…
- CVE-2022-43910HIGHCVSS 8.4EG 8.42023-07-19
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908.
- CVE-2022-44020MEDIUMCVSS 5.5EG 5.52022-10-30
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affec…
- CVE-2022-47547MEDIUMCVSS 5.3EG 5.32022-12-19
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbehaves by never forwarding topic messages.
- CVE-2022-47637MEDIUMCVSS 6.7EG 6.72023-09-12
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.
- CVE-2022-48295HIGHCVSS 7.5EG 7.52023-02-09
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).
- CVE-2022-48296MEDIUMCVSS 5.3EG 5.32023-02-09
The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.
- CVE-2022-48301HIGHCVSS 7.5EG 7.52023-02-09
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.
- CVE-2023-0975HIGHCVSS 8.2EG 8.22023-04-03
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevat…
- CVE-2023-1386LOWCVSS 3.3EG 3.32023-07-24
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumst…
- CVE-2023-21249MEDIUMCVSS 5.5EG 5.52023-07-13
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interac…
- CVE-2023-21464MEDIUMCVSS 4.0EG 4.02023-03-16
Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.
- CVE-2023-22738MEDIUMCVSS 6.3EG 6.32023-03-01
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may lead to unintended access: if a user from organization A is…
- CVE-2023-25646HIGHCVSS 7.1EG 7.12024-06-20
There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by p…
- CVE-2023-25809MEDIUMCVSS 5.0EG 5.02023-03-29
runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that rootless runc makes `/sys/fs/cgroup` writable in following conditons: 1. when runc is executed inside the use…
- CVE-2023-25812MEDIUMCVSS 6.5EG 6.52023-02-21
Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all users attempting to DELETE a versionId with the special head…
- CVE-2023-25817LOWCVSS 3.5EG 3.52023-03-27
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This is…
- CVE-2023-28161HIGHCVSS 8.8EG 8.82023-06-02
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dan…
- CVE-2023-2818MEDIUMCVSS 5.5EG 5.52023-06-27
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffect…
- CVE-2023-28642MEDIUMCVSS 6.1EG 6.12023-03-29
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been f…
- CVE-2023-28646MEDIUMCVSS 4.4EG 4.42023-03-30
Nextcloud android is an android app for interfacing with the nextcloud home server ecosystem. In versions from 3.7.0 and before 3.24.1 an attacker that has access to the unlocked physical device can bypass the Nextcloud Android Pin/passcod…
- CVE-2023-28647MEDIUMCVSS 4.4EG 4.42023-03-30
Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app an…
- CVE-2023-28668CRITICALCVSS 9.8EG 9.82023-04-02
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
- CVE-2023-2993MEDIUMCVSS 5.4EG 5.42023-06-26
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient …
- CVE-2023-30735MEDIUMCVSS 5.1EG 5.12023-10-04
Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.
- CVE-2023-31923HIGHCVSS 8.8EG 8.82023-05-22
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is cau…
- CVE-2023-31926HIGHCVSS 7.1EG 7.12023-08-02
System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.
- CVE-2023-32199MEDIUMCVSS 4.3EG 4.32025-10-29
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Glo…
- CVE-2023-32355MEDIUMCVSS 5.5EG 5.52023-06-23
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system.
- CVE-2023-32388MEDIUMCVSS 5.5EG 5.52023-06-23
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5…
- CVE-2023-32400MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
- CVE-2023-32552MEDIUMCVSS 5.3EG 5.32023-06-26
An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identica…
- CVE-2023-34034CRITICALCVSS 9.1EG 9.12023-07-19
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
- CVE-2023-34672HIGHCVSS 8.8EG 8.82023-06-23
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.
- CVE-2023-35938MEDIUMCVSS 4.1EG 4.12023-06-29
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching from a project visibility that allows restricted users to `Private without restricted`, restricted users that are projec…
- CVE-2023-36387MEDIUMCVSS 5.4EG 5.42023-09-06
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
Map vulnerabilities like CWE-281 to your infrastructure
EchelonGraph correlates every CVE — across CWE-281 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →