← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openatom
1Openharmony
Jun 17, 2026
Nov 20, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332.
1Concretecms
1Concrete Cms
Jun 17, 2026
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777...Show more
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.Show less
1Autelrobotics
1Evo Nano Drone Firmware
Jun 17, 2026
Nov 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones.
1Ivanti
1Secure Access Client
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
1Ivanti
1Secure Access Client
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, inc...Show more
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.Show less
1Intel
1Arc Rgb Controller
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
2Arc A Graphics
Iris Xe Graphics
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
3Debian
IntelNetapp
223Affa900 Firmware
Core I3 1005g1 FirmwareCore I3 10100y Firmware+220 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of se...Show more
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.Show less
2Emsigner
Emudhra
2Emsigner
Emsigner
Aug 28, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a cr...Show more
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.Show less
1Xwiki
1Application Collabora
Jun 17, 2026
Nov 9, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments file...Show more
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments files in view or edit mode. Currently, if a user opens an attachment file in edit mode in collabora, this right will be preserved for all future users, until the editing session is closes, even if some of them have only view right. Collabora server is the one issuing this request and it seems that the `userCanWrite` query parameter is cached, even if, for example, token is not. This issue has been patched in version 1.3.Show less
1Lenovo
1Preload Directory
Jun 17, 2026
Nov 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.
1Advanced Export Products Orders Cron Csv Excel Project
1Advanced Export Products Orders Cron Csv Excel
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
1Ivanti
1Avalanche
Jun 17, 2026
Nov 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
3Fedoraproject
RedhatSamba
5Enterprise Linux
Enterprise Linux EusFedora+2 more
Jun 17, 2026
Nov 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes"....Show more
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions.Show less
1Lenovo
13Thinkpad 25 Firmware
Thinkpad L560 FirmwareThinkpad P50 Firmware+10 more
Jun 17, 2026
Oct 30, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Sec...Show more
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot. Show less
1Tenable
1Nessus Network Monitor
Jun 17, 2026
Oct 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location
1Wenwen Ai
1Wenwenai Cms
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.
1Ellipticlabs
2Ai Virtual Presence Sensor
Virtual Lock Sensor
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
1Tinylab
2Cloud Lab
Linux Lab
Jun 17, 2026
Oct 19, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.