← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Linuxfoundation
2Fedora
Runc
Jun 17, 2026
May 17, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linu...Show more
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.Show less
1Fidelissecurity
2Deception
Network
Jun 17, 2026
May 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which coul...Show more
Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.Show less
1Fidelissecurity
2Deception
Network
Jun 17, 2026
May 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enabl...Show more
Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.Show less
1Nextcloud
1Talk
Jun 17, 2026
May 17, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removin...Show more
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.Show less
1Simple Social Networking Site Project
1Simple Social Networking Site
Jun 17, 2026
May 13, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
1Air Cargo Management System Project
1Air Cargo Management System
Jun 17, 2026
May 13, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
1Ijoomla
1Guru
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' inf...Show more
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private information and components, possibility to view other users' information.Show less
1Mahara
1Mahara
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being...Show more
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).Show less
1Ciphermail
1Webmail Messenger
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-fac...Show more
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Apr 22, 2022
N/A· v4
5.0 MEDIUM· v3
4.7 MEDIUM· v2
A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to non-standard locations during installation.
1Cisco
1Virtualized Infrastructure Manager
Jun 17, 2026
Apr 21, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker to access confidential information and elevate privileges on an affecte...Show more
A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker to access confidential information and elevate privileges on an affected device. This vulnerability is due to improper access permissions for certain configuration files. An attacker with low-privileged credentials could exploit this vulnerability by accessing an affected device and reading the affected configuration files. A successful exploit could allow the attacker to obtain internal database credentials, which the attacker could use to view and modify the contents of the database. The attacker could use this access to the database to elevate privileges on the affected device.Show less
1Mediawiki
1Createredirect
Jun 17, 2026
Apr 21, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a pag...Show more
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.Show less
1Fanuc
1Roboguide
Jun 17, 2026
Apr 20, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.
1Liferay
2Digital Experience Platform
Liferay Portal
Jul 9, 2026
Apr 19, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view s...Show more
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.Show less
4Fedoraproject
KubernetesMobyproject+1 more
4Cri O
FedoraMoby+1 more
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable L...Show more
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.Show less
1Wordpress
1Wordpress
Nov 21, 2024
Apr 18, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'pub...Show more
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.Show less
1Google
1Android
Jun 17, 2026
Apr 12, 2022
N/A· v4
7.8 HIGH· v3
7.6 HIGH· v2
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privile...Show more
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-205836329Show less
1Samsung
1Recovery
Jun 17, 2026
Apr 11, 2022
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.
1Discourse
1Discourse
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set...Show more
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set the permissions of a category, the name of the group is leaked to any user that is able to see the category. To workaround the problem, a site administrator can remove groups with restricted visibility from any category's permissions setting.Show less
1Ofcms Project
1Ofcms
Jun 17, 2026
Apr 10, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.