← Back
CWE-276

1,529 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Confluence
May 13, 2026
Jun 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive w...Show more
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.Show less
1Pivotal
1Pcf Tile Generator
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.
1Schneider Electric
1Wonderware Indusoft Web Studio
May 13, 2026
May 19, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and tw...Show more
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.Show less
1Intel
2Nuc6i3syh Bios
Nuc6i3syk Bios
May 13, 2026
Apr 3, 2017
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an attacker with physical access to the system to gain access to personal information.
1Intel
1Nuc6i7kyk Bios
May 13, 2026
Apr 3, 2017
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an attacker with physical access to the system to gain access to personal information.
1Intel
1Stk2mv64cc Bios
May 13, 2026
Apr 3, 2017
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attacker with physical access to the system to gain access to personal information.
1Apache
1Ambari
May 13, 2026
Apr 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
1Oneplus
1Oxygenos
May 13, 2026
Mar 26, 2017
N/A· v4
5.9 MEDIUM· v3
3.6 LOW· v2
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authoriza...Show more
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.Show less
1Veritas
2Netbackup
Netbackup Appliance
May 13, 2026
Mar 2, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction or spoofing of log data.
1Apache
1Tomcat
May 6, 2026
Oct 13, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain ro...Show more
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.Show less
1Watchguard
1Panda Endpoint Administration Agent
May 6, 2026
Apr 18, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to g...Show more
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module.Show less
1Watchguard
1Panda Url Filtering
May 6, 2026
Apr 18, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.
1Valvesoftware
1Steam Client
May 6, 2026
Nov 24, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.
2Debian
Systemd Project
2Debian Linux
Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
5.9 MEDIUM· v2
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the X...Show more
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."Show less
1Openstack
2Essex
Folsom
Apr 30, 2026
Mar 8, 2013
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configu...Show more
A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.Show less
1Adobe
1Coldfusion
Apr 21, 2026
Jan 17, 2013
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and...Show more
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.Show less
3Dracut Project
FedoraprojectRedhat
5Dracut
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive infor...Show more
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Apr 29, 2026
Jan 8, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning fun...Show more
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.Show less
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspe...Show more
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.Show less