← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Clickstudios
1Passwordstate
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a p...Show more
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.Show less
1Google
1Sa360 Webquery To Bigquery Exporter
Jun 17, 2026
Mar 18, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
1Gradle
1Enterprise
Jun 17, 2026
Mar 17, 2022
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potent...Show more
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build. As of 2021.4.2, the built-in build cache is inaccessible-by-default, requiring explicit configuration of its access-control settings before it can be used. (Remote build cache nodes are unaffected as they are inaccessible-by-default.)Show less
1Google
1Android
Jun 17, 2026
Mar 16, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional exec...Show more
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-202312327Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
1Google
1Android
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
1Northern.tech
1Cfengine
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
1Northern.tech
1Cfengine
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
2Fedoraproject
Gnu
2Fedora
Grub2
Jun 17, 2026
Mar 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality...Show more
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.Show less
1Secomea
1Gatemanager
Jun 17, 2026
Mar 10, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored Si...Show more
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.Show less
1Kexec Tools Project
1Kexec Tools
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from t...Show more
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.Show less
1Kingsoft
1Wps Office
Jun 17, 2026
Mar 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.
1Liferay
2Digital Experience Platform
Liferay Portal
Jul 9, 2026
Mar 2, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permission...Show more
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.Show less
1Batflat
1Batflat
Jun 17, 2026
Mar 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.
1Jetbrains
1Youtrack
Jun 17, 2026
Feb 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.