← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Jira Align
Jun 17, 2026
Oct 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This v...Show more
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.Show less
2Bushnellgolf
Foresightsports
2Gc3 Launch Monitor Firmware
Launch Pro Firmware
Jun 17, 2026
Oct 13, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, a...Show more
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the known passphrase of FSSPORTS, an attacker could use this service to modify a device and steal intellectual property.Show less
1Dell
1Geodrive
Jun 17, 2026
Oct 12, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in th...Show more
Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context. Dell recommends customers to upgrade at the earliest opportunity.Show less
1Google
1Android
Jun 17, 2026
Oct 11, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369
1Google
1Android
Jun 17, 2026
Oct 11, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android...Show more
There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android SoCAndroid ID: A-242248367Show less
1Trendmicro
1Apex One
Jun 17, 2026
Oct 10, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering m...Show more
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affected installations. Please note: an attacker must first obtain administrative credentials on the target system in order to exploit this vulnerability.Show less
1Liferay
1Liferay Portal
Jun 17, 2026
Oct 7, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
1Beckmancoulter
1Remisol Advance
Jun 17, 2026
Oct 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate...Show more
A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate executables and libraries that run as the elevated SYSTEM user on Windows.Show less
1Measuresoft
1Scadapro Server
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with...Show more
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.Show less
1Huawei
1Jad Al50 Firmware
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220...Show more
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).Show less
1Trendmicro
1Housecall
Jun 17, 2026
Sep 19, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.
1Siemens
1Coreshield One Way Gateway
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to...Show more
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.Show less
1Octopus
1Octopus Server
Jun 17, 2026
Sep 9, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.
1Opensuse
1Factory
Jun 17, 2026
Sep 7, 2022
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory...Show more
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.Show less
2Clusterlabs
Debian
2Debian Linux
Pcs
Jun 17, 2026
Sep 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authe...Show more
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.Show less
1Totolink
1A3002r Firmware
Jun 17, 2026
Sep 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
1Influxdata
1Influxdb
Jul 9, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's document...Show more
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."Show less
2Fedoraproject
Samba
2Fedora
Samba
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
1Vim
1Gvim
Jun 17, 2026
Aug 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
2Fedoraproject
Samba
2Fedora
Samba
Jun 17, 2026
Aug 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account mo...Show more
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.Show less