← Back
CWE-277

71 CVEs • Abstraction: Variant

Insecure Inherited Permissions

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

JSON object

Loading...

CVEs (71)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence...Show more
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerability does not disclose any sensitive data.Show less
1Dell
1Wyse Management Suite
Jun 17, 2026
Apr 2, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauth...Show more
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.Show less
1Apple
1Macos
Jun 17, 2026
Mar 21, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.
1Ibm
1Robotic Process Automation
Jun 17, 2026
Jan 18, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and...Show more
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A subsequent service or server restart will then run that binary with administrator privilege.Show less
1Intel
1Driver & Support Assistant
Jun 17, 2026
Nov 13, 2024
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Computing Improvement Program
Jun 17, 2026
Nov 13, 2024
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.
-
-
Jun 17, 2026
Sep 25, 2024
N/A· v4
3.8 LOW· v3
N/A· v2
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or...Show more
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly being granted access, through a DyLib Injection using DYLD_INSERT_LIBRARIES environment variable. The usage of `com.apple.security.cs.allow-dyld-environment-variables` and `com.apple.security.cs.disable-library-validation` allows an external dynamic library to be injected into the application using DYLD_INSERT_LIBRARIES environment variable. Moreover, the entitlement `com.apple.security.device.camera` allows the application to use the host camera and `com.apple.security.device.audio-input` allows the application to use the microphone. This means that untrusted code that is executed on the user's machine can access the camera or the microphone, if the user has already given permission for Cursor to do so. In version 0.41.0, the entitlements have been split by process: the main process gets the camera and microphone entitlements, but not the DyLib entitlements, whereas the extension host process gets the DyLib entitlements but not the camera or microphone entitlements. As a workaround, do not explicitly give Cursor the permission to access the camera or microphone if untrusted users can run arbitrary commands on the affected machine.Show less
1Xuxueli
1Xxl Job
Jun 17, 2026
Aug 15, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
1Intel
10Hid Event Filter Driver
Nuc M15 Laptop Kit Lapbc510 FirmwareNuc M15 Laptop Kit Lapbc710 Firmware+7 more
Jun 17, 2026
Aug 14, 2024
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Flexlm License Daemons For Intel Fpga
Jun 17, 2026
Aug 14, 2024
5.4 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Pulpproject
1Pulp
Jun 17, 2026
Aug 7, 2024
N/A· v4
8.3 HIGH· v3
N/A· v2
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator me...Show more
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.Show less
-
-
Jun 17, 2026
Jul 25, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
1External Secrets
1External Secrets Operator
Jun 17, 2026
Jul 24, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
1Projectcontour
1Contour
Jun 17, 2026
Jul 24, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
-
-
Jun 17, 2026
Jul 22, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.
-
-
Jun 17, 2026
Jul 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
1Apache
1Airflow
Jun 17, 2026
Jul 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be...Show more
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to version 2.9.3 or later which has removed the vulnerability.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
-
-
Jun 17, 2026
Jun 12, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.
1Apple
3Ipados
Iphone OsMacos
Jun 17, 2026
Jun 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.