CWE-281— Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.— MITRE CWE catalog
358 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-281page 6 of 8
- CVE-2024-38361LOWCVSS 3.7EG 3.72024-06-20
Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when per…
- CVE-2024-39902MEDIUMCVSS 4.8EG 4.82024-07-22
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the checkbox "Apply same permissions to all s…
- CVE-2024-40672HIGHCVSS 8.4EG 8.42025-01-28
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
- CVE-2024-40770HIGHCVSS 7.5EG 7.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted network settings.
- CVE-2024-40800HIGHCVSS 5.5EG 8.42024-07-29
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
- CVE-2024-40805HIGHCVSS 7.1EG 7.72024-07-29
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
- CVE-2024-40811HIGHCVSS 5.5EG 8.42024-07-29
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.
- CVE-2024-40821HIGHCVSS 7.1EG 8.42024-07-29
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.
- CVE-2024-40824HIGHCVSS 5.5EG 7.72024-07-29
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
- CVE-2024-40828HIGHCVSS 7.8EG 8.42024-07-29
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious app may be able to gain root privileges.
- CVE-2024-40831MEDIUMCVSS 5.5EG 5.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access a user's Photos Library.
- CVE-2024-40859MEDIUMCVSS 5.5EG 5.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.
- CVE-2024-41644CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.
- CVE-2024-41645CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.
- CVE-2024-41646CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.
- CVE-2024-41648CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.
- CVE-2024-41649CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.
- CVE-2024-41650CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.
- CVE-2024-43784MEDIUMCVSS 5.7EG 5.72024-11-26
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the…
- CVE-2024-44149HIGHCVSS 7.5EG 7.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.
- CVE-2024-44188MEDIUMCVSS 5.5EG 5.52024-09-17
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.
- CVE-2024-44193HIGHCVSS 7.8EG 8.42024-10-02
A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.
- CVE-2024-44211HIGHCVSS 5.5EG 7.52024-12-20
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.
- CVE-2024-44223MEDIUMCVSS 4.6EG 4.62024-12-20
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.
- CVE-2024-46310CRITICALCVSS 9.1EG 9.12025-01-13
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
- CVE-2024-46622CRITICALCVSS 9.8EG 9.82025-01-06
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arbitrary file creation, modification and d…
- CVE-2024-46941MEDIUMCVSS 4.8EG 4.82025-06-06
SystemUI has an incorrect component protection setting, which allows access to specific information.
- CVE-2024-47270LOWCVSS 2.7EG 2.72026-05-27
Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via…
- CVE-2024-4768MEDIUMCVSS 6.1EG 6.12024-05-14
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- CVE-2024-50920HIGHCVSS 8.8EG 8.82024-12-10
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
- CVE-2024-50921MEDIUMCVSS 6.5EG 6.52024-12-10
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.
- CVE-2024-50924MEDIUMCVSS 6.5EG 6.52024-12-10
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.
- CVE-2024-50928MEDIUMCVSS 6.5EG 6.52024-12-10
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.
- CVE-2024-50929MEDIUMCVSS 6.2EG 6.22024-12-10
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).
- CVE-2024-50930HIGHCVSS 8.8EG 8.82024-12-10
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
- CVE-2024-50931MEDIUMCVSS 4.6EG 4.62024-12-10
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
- CVE-2024-52522MEDIUMCVSS 5.4EG 5.42024-11-15
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indi…
- CVE-2024-52869MEDIUMCVSS 6.0EG 6.02025-01-08
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3…
- CVE-2024-53355HIGHCVSS 8.8EG 8.82025-01-31
Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /…
- CVE-2024-53934HIGHCVSS 7.7EG 7.72025-01-06
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a c…
- CVE-2024-53994MEDIUMCVSS 4.3EG 4.32025-02-04
Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are a…
- CVE-2024-54465CRITICALCVSS 9.8EG 9.82024-12-12
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.
- CVE-2024-54484MEDIUMCVSS 5.5EG 5.52024-12-12
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.
- CVE-2024-54513MEDIUMCVSS 5.5EG 5.72024-12-12
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access sensitive user data.
- CVE-2024-54515HIGHCVSS 7.8EG 7.82024-12-12
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.
- CVE-2024-54516LOWCVSS 3.3EG 3.32025-01-27
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to approve a launch daemon without user consent.
- CVE-2024-54557HIGHCVSS 7.5EG 7.52025-01-27
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An attacker may gain access to protected parts of the file system.
- CVE-2024-54818HIGHCVSS 8.8EG 8.82025-01-08
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.
- CVE-2024-54879CRITICALCVSS 9.1EG 9.12025-01-06
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
- CVE-2024-54880CRITICALCVSS 9.1EG 9.12025-01-06
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
Map vulnerabilities like CWE-281 to your infrastructure
EchelonGraph correlates every CVE — across CWE-281 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →