← Back
CWE-276

1,508 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,508)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Emui
Harmonyos
Mar 13, 2025
Apr 7, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
-
-
Mar 13, 2025
Apr 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.
1Macro Expert
1Macro Expert
Jan 30, 2026
Apr 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivileged user can escalate to SYSTEM by replacing the MacroService.exe binary.
1Fortra
1Robot Schedule
Apr 9, 2025
Mar 28, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced b...Show more
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges. Show less
1Dell
1Grab
Jan 28, 2025
Mar 26, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege esca...Show more
Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data, unauthorized modification of application data and service disruption.Show less
2Debian
Gnu
3Debian Linux
EmacsOrg Mode
May 1, 2025
Mar 25, 2024
N/A· v4
2.8 LOW· v3
N/A· v2
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
1Elspec Ltd
1G5dfr Firmware
Apr 16, 2025
Mar 20, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.
1Avsystem
1Unified Management Platform
Mar 14, 2025
Mar 18, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, an...Show more
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.Show less
1Bmc
1Control M
Mar 6, 2025
Mar 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malic...Show more
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.Show less
1Rotp Project
1Rotp
Apr 3, 2026
Mar 16, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. User...Show more
The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.Show less
-
-
Nov 4, 2025
Mar 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Microsoft
1Windows Defender Antimalware Platform
Nov 29, 2024
Mar 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Microsoft Defender Security Feature Bypass Vulnerability
1Apple
1Visionos
Apr 2, 2026
Mar 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.
1Apple
1Macos
Apr 2, 2026
Mar 8, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.
1Apple
5Ipados
Iphone OsMacos+2 more
Apr 2, 2026
Mar 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able...Show more
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.Show less
1Plone
1Plone
Jan 21, 2025
Mar 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
1Samsung
1Account
Feb 14, 2025
Mar 5, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
1Samsung
1Android
Feb 10, 2025
Mar 5, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
1Google
1Android
Apr 22, 2025
Mar 4, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. P...Show more
In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355599; Issue ID: ALPS08355599.Show less
1Apache
1Airflow
May 13, 2025
Mar 1, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2....Show more
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2.8.2 and newer, Ops and Viewer users do not have audit log permission by default, they need to be explicitly granted permissions to see the logs. Only admin users have audit log permission by default. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerabilityShow less