← Back
CWE-276

1,529 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Feb 10, 2026
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalat...Show more
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.Show less
-
-
Jun 17, 2026
Feb 9, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative tru...Show more
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each time settings are fetched. The code coerces any truthy value to true and forwards it to ConfigLoader.setIsTrusted , which in turn allows JavaScript/TypeScript configuration files ( .cspell.config.js/.mjs/.ts , etc.) to be located and executed. Because no VS Code workspace-trust state is consulted, an untrusted workspace can keep the flag true and place a malicious .cspell.config.js ; opening the workspace causes the extension host to execute attacker-controlled Node.js code with the user’s privileges. This vulnerability is fixed in v4.5.4.Show less
-
-
Jun 17, 2026
Feb 7, 2026
8.5 HIGH· v4
6.2 MEDIUM· v3
N/A· v2
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and w...Show more
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.Show less
1Tanium
1Enforce
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Enforce.
1Tanium
1Benchmark
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
1Tanium
1Comply
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Comply.
1Tanium
1Discover
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Discover.
1Tanium
1Partner Integration
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
1Tanium
1Patch
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Patch.
1Tanium
1Performance
Jun 17, 2026
Feb 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tanium addressed an incorrect default permissions vulnerability in Performance.
1Tanium
1Threat Response
Jun 17, 2026
Feb 5, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Tanium addressed an information disclosure vulnerability in Threat Response.
1Tanium
1Threat Response
Jun 17, 2026
Feb 5, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Tanium addressed an information disclosure vulnerability in Threat Response.
1Tanium
1Threat Response
Jun 17, 2026
Feb 5, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Tanium addressed an information disclosure vulnerability in Threat Response.
-
-
Jun 17, 2026
Feb 5, 2026
8.5 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during s...Show more
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.Show less
-
-
Jun 17, 2026
Feb 5, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing servi...Show more
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing service executable files (EXE) or DLLs in the installation directory with specially crafted files. As a result, the attacker may be able to disclose, tamper with, delete, or destroy information stored on the PC where the affected product is installed, or cause a Denial of Service (DoS) condition on the affected system.Show less
1Shirt Pocket
1Superduper!
Jul 5, 2026
Jan 29, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thu...Show more
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.Show less
1Agpt
1Autogpt Platform
Jun 17, 2026
Jan 29, 2026
8.6 HIGH· v4
8.8 HIGH· v3
N/A· v2
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution...Show more
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID without checking the `disabled` flag. Any authenticated user can execute the disabled `BlockInstallationBlock`, which writes arbitrary Python code to the server filesystem and executes it via `__import__()`, achieving Remote Code Execution. In default self-hosted deployments where Supabase signup is enabled, an attacker can self-register; if signup is disabled (e.g., hosted), the attacker needs an existing account. autogpt-platform-beta-v0.6.44 contains a fix.Show less
1Icinga
1Icinga Powershell Framework
Jun 17, 2026
Jan 29, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for...Show more
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of private key of the Icinga certificate for the given host. All installations are affected. Versions 1.13.4, 1.12.4, and 1.11.2 contains a patch. Please note that upgrading to a fixed version of Icinga for Windows will also automatically fix a similar issue present in Icinga 2, CVE-2026-24413. As a workaround, the permissions can be restricted manually by updating the ACL for the given folder `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` (and `C:\ProgramData\icinga2\var` to fix the issue for the Icinga 2 agent as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.Show less
1Icinga
1Icinga
Jun 17, 2026
Jan 29, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder o...Show more
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work around the issue without upgrading Icinga 2. Upgrade Icinga for Windows to at least version v1.13.4, v1.12.4, or v1.11.2. These version will automatically fix the ACLs for the Icinga 2 agent as well. Alternatively, manually update the ACL for the given folder `C:\ProgramData\icinga2\var` (and `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` to fix the issue for the Icinga for Windows as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.Show less
-
-
Jun 17, 2026
Jan 29, 2026
7.0 HIGH· v4
N/A· v3
N/A· v2
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a loca...Show more
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.Show less