← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Spectrum Protect
Spectrum Protect For Virtual Environments
Nov 21, 2024
Nov 25, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551.
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
1Python
1Keyring
Nov 21, 2024
Nov 25, 2019
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
Python keyring has insecure permissions on new databases allowing world-readable files to be created
1Vtiger
1Vtiger Crm
Jun 17, 2026
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
1Zohocorp
2Manageengine Firewall Analyzer
Manageengine Opmanager
Jun 17, 2026
Nov 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a mal...Show more
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.Show less
3Debian
FedoraprojectRedhat
7Debian Linux
Enterprise LinuxEnterprise Linux Desktop+4 more
Nov 21, 2024
Nov 20, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
1Intel
1Nuvoton Consumer Infrared
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
2Debian
Edgewall
2Debian Linux
Trac
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions....Show more
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.Show less
2Debian
Ldap Git Backup Project
2Debian Linux
Ldap Git Backup
Nov 21, 2024
Nov 7, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
1Cisco
4Firepower Services Software For Asa
Firepower Threat DefenseSecure Firewall Management Center+1 more
Aug 11, 2026
Nov 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated...Show more
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper handling of HTTP requests, including those communicated over a secure HTTPS connection, that contain maliciously crafted headers. An attacker could exploit this vulnerability by sending malicious requests to an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious requests to protected systems, allowing attackers to deliver malicious content that would otherwise be blocked.Show less
1Symantec
1Sonar
Jun 17, 2026
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.1 MEDIUM· v2
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident...Show more
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
2Debian
Python
2Debian Linux
Keyring
Nov 21, 2024
Oct 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Python keyring lib before 0.10 created keyring files with world-readable permissions.
2Inea
Mitsubishielectric
2Me Rtu Firmware
Smartrtu Firmware
Jun 17, 2026
Oct 28, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an...Show more
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment.Show less
1Jenkins
1Global Post Script
Jun 17, 2026
Oct 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.
1Jenkins
1Libvirt Slaves
Jun 17, 2026
Oct 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.