← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Fscrypt
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by cre...Show more
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or aboveShow less
1Win 911
2Win 911 2021 R1
Win 911 2021 R2
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer directory and elevate permissions whenever the program is executed.
1Win 911
2Win 911 2021 R1
Win 911 2021 R2
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Workspace directory, which holds DLL files and executables. A low-privileg...Show more
WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Workspace directory, which holds DLL files and executables. A low-privilege attacker could write a malicious DLL file to the Operator Workspace directory to achieve privilege escalation and the permissions of the user running the program.Show less
2Cobbler Project
Fedoraproject
2Cobbler
Fedora
Jun 17, 2026
Feb 20, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the se...Show more
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.Show less
2Konveyor
Redhat
2Mig Controller
Migration Toolkit
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting con...Show more
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.Show less
1Canonical
2Snapd
Ubuntu Linux
Jun 17, 2026
Feb 17, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd...Show more
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1Show less
2Debian
Skolelinux
2Debian Edu Config
Debian Linux
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privile...Show more
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.Show less
1Samsung
1Wear Os
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.
1Samsung
1Wear Os
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
1Google
1Android
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this...Show more
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system properties。Product: AndroidVersions: Android SoCAndroid ID: A-207479207Show less
1Google
1Android
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage V...Show more
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634Show less
1Mitsubishielectric
46C Controller Interface Module Utility
C Controller Module Setting And Monitoring ToolCc Link Ie Control Network Data Collector+43 more
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, an...Show more
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.Show less
1Intel
1Quartus Prime
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Retail Experience Tool
Jun 17, 2026
Feb 9, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
1Advisor
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Schneider Electric
37Hmibmiea5dd1001 Firmware
Hmibmiea5dd100a FirmwareHmibmiea5dd1101 Firmware+34 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (A...Show more
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)Show less
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
1Acronis
4Agent
Cyber ProtectCyber Protect Home Office+1 more
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147,...Show more
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287Show less
2Debian
Minetest
2Debian Linux
Minetest
Jun 17, 2026
Feb 2, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.
1Elitecms
1Elite Cms
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.