← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Mar 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an a...Show more
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.Show less
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interaction V-2022-002.
1Huawei
1Harmonyos
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
1Harmonyos
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
1Harmonyos
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
1Harmonyos
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
1Harmonyos
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.
1Spotipy Project
1Spotipy
Jun 17, 2026
Feb 27, 2025
8.4 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created has `rw-r--r--` (644) permissions by defau...Show more
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created has `rw-r--r--` (644) permissions by default, when it could be locked down to `rw-------` (600) permissions. This leads to overly broad exposure of the spotify auth token. If this token can be read by an attacker (another user on the machine, or a process running as another user), it can be used to perform administrative actions on the Spotify account, depending on the scope granted to the token. Version 2.25.1 tightens the cache file permissions.Show less
-
-
Jun 17, 2026
Feb 24, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor pl...Show more
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.Show less
1Dell
1Recoverpoint For Virtual Machines
Jun 17, 2026
Feb 20, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive re...Show more
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.Show less
1Mayswind
1Ezbookkeeping
Jun 17, 2026
Feb 12, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
-
-
Jun 17, 2026
Feb 12, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 12, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary c...Show more
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.Show less
1Jrohy
1Trojan
Jun 17, 2026
Feb 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
-
-
Jun 17, 2026
Feb 4, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to esca...Show more
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.Show less
-
-
Jun 17, 2026
Jan 31, 2025
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as root by default, the...Show more
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as root by default, there is no limit to what can be overwritten. With this, it's possible to inject malicious payloads into files ran on schedule or upon certain service actions. As the service is not required to run with authentication enabled, this may permit wholly unprivileged users root access. Otherwise, anybody with a PIN.Show less