← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Coreos Installer
Jun 17, 2026
Aug 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive da...Show more
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.Show less
1Redhat
1Ansible Runner
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading priva...Show more
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity.Show less
1Planex
1Mzk Dp150n Firmware
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.
1Intel
1Support
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.
1Intel
1Single Event Api
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Open Active Management Technology Cloud Toolkit
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
1Intel
1Connect M
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Aug 16, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission cont...Show more
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.Show less
1Power Software Download
1Viewpower
Jun 17, 2026
Aug 16, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.
1Google
1Android
Jun 17, 2026
Aug 12, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User i...Show more
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-207672568Show less
1Google
1Android
Jun 17, 2026
Aug 11, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional e...Show more
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230493191Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
1Grommunio
1Gromox
Jun 17, 2026
Aug 4, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading t...Show more
Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM module.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jul 20, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Jul 12, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
1Mattermost
1Mattermost Server
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the...Show more
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.Show less
6Apple
DebianFedoraproject+3 more
14Bootstrap Os
Clustered Data OntapCurl+11 more
Jun 17, 2026
Jul 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.Show less