CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332. |
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777...Show more |
1Autelrobotics 1Evo Nano Drone Firmware Jun 17, 2026 Nov 16, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones. |
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. |
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, inc...Show more |
Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 2Arc A Graphics Iris Xe GraphicsJun 17, 2026 Nov 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. |
3Debian IntelNetapp223Affa900 Firmware Core I3 1005g1 FirmwareCore I3 10100y Firmware+220 moreJun 17, 2026 Nov 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of se...Show more |
2Emsigner Emudhra2Emsigner EmsignerAug 28, 2026 Nov 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a cr...Show more |
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments file...Show more |
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.
|
1Advanced Export Products Orders Cron Csv Excel Project 1Advanced Export Products Orders Cron Csv Excel Jun 17, 2026 Nov 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table. |
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes"....Show more |
1Lenovo 13Thinkpad 25 Firmware Thinkpad L560 FirmwareThinkpad P50 Firmware+10 moreJun 17, 2026 Oct 30, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Sec...Show more |
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location
|
Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges. |
1Ellipticlabs 2Ai Virtual Presence Sensor Virtual Lock SensorJun 17, 2026 Oct 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges. |
TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape. |