← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Devolutions
1Devolutions Server
Jun 17, 2026
Jul 7, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
1Gitlab
1Gitlab
Jun 17, 2026
Jul 1, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan pack...Show more
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.Show less
1Openhwgroup
1Cva6
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
1Melag
1Ftp Server
Jun 17, 2026
Jun 24, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
1Melag
1Ftp Server
Jun 17, 2026
Jun 24, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
1Redhat
1Amq Broker
Jun 17, 2026
Jun 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by che...Show more
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building the Operator gives more permission than expected and an attacker could benefit from it. This requires at least an already compromised low-privilege account or insider attack.Show less
2Checkmk
Tribe29
2Checkmk
Checkmk
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents...Show more
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/ will be owned by the user and the group with ID 1001. If such a user exists on the system, they can change the content of these files (which are then executed by root). This leads to a local privilege escalation on the monitored host. Version 1.6 through 1.6.9p29, version 2.0 through 2.0.0p26, version 2.1 through 2.1.0p3, and version 2.2.0i1 are affected.Show less
1Octokit Project
1Octokit
Jun 17, 2026
Jun 15, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-r...Show more
Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. This issue is patched in Octokit 4.25.0. Two workarounds are available. Users can use the previous version of the gem, v4.22.0. Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.Show less
1Octopoller Project
1Octopoller
Jun 17, 2026
Jun 15, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-...Show more
Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. This issue is patched in Octopoller 0.3.0. Two workarounds are available. Users can use the previous version of the gem, v0.1.0. Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
1Igel
1Universal Management Suite
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKEY_LOCAL_MACHINE\SOFTWARE) allow an unpri...Show more
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKEY_LOCAL_MACHINE\SOFTWARE) allow an unprivileged local attacker to read the encrypted dbuser and dbpassword values for the UMS superuser.Show less
1Samsung
1Smartthings
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.
1Knime
1Knime Analytics Platform
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
1Abb
1E Design
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
1Abb
1E Design
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
1Apachefriends
1Xampp
Jun 17, 2026
May 23, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.
1Bloodshed
1Dev C++
Jun 17, 2026
May 23, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe.
1Dlink
1Dsl G2452dg Firmware
Jul 9, 2026
May 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
1Cilium
1Cilium
Jun 17, 2026
May 20, 2022
N/A· v4
8.2 HIGH· v3
4.6 MEDIUM· v2
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissi...Show more
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissions vulnerability. Operating Systems with users belonging to the group ID 1000 can access the API of Cilium via Unix domain socket available on the host where Cilium is running. This could allow malicious users to compromise integrity as well as system availability on that host. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. A potential workaround is to modify Cilium's DaemonSet to run with a certain command, which can be found in the GitHub Security Advisory for this vulnerability.Show less