← Back
CWE-281

337 CVEs • Abstraction: Base

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

JSON object

Loading...

CVEs (337)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apachefriends
1Xampp
Jun 17, 2026
Sep 12, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.
1Jenkins
1Ssh2 Easy
Jun 17, 2026
Sep 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access...Show more
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.Show less
1Broadcom
1Brocade Fabric Operating System
Jun 17, 2026
Aug 2, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.
2Fedoraproject
Qemu
2Fedora
Qemu
Jun 17, 2026
Jul 24, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a resul...Show more
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.Show less
1Vmware
1Spring Security
Jun 17, 2026
Jul 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
1Ibm
1Security Guardium
Jun 17, 2026
Jul 19, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908.
1Google
1Android
Jun 17, 2026
Jul 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges n...Show more
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Show less
1Enalean
1Tuleap
Jun 17, 2026
Jun 29, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching from a project visibility that allows restricted users to `Private without restricted`, restricted us...Show more
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching from a project visibility that allows restricted users to `Private without restricted`, restricted users that are project administrators keep this access right. Restricted users that were project administrators before the visibility switch keep the possibility to access the project and do some administration actions. This issue has been resolved in Tuleap version 14.9.99.63. Users are advised to upgrade. There are no known workarounds for this issue.Show less
1Proofpoint
1Insider Threat Management
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and...Show more
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.Show less
1Trendmicro
1Apex One
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar t...Show more
An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32553Show less
1Lenovo
8Nextscale N1200 Enclosure Firmware
Thinkagile Cp Cb 10 FirmwareThinkagile Cp Cb 10e Firmware+5 more
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normal...Show more
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.Show less
1Elenos
1Etg150 Firmware
Jul 9, 2026
Jun 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Inter...Show more
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.Show less
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 1...Show more
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.Show less
1Apple
1Macos
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify protected parts of the file system.
1Mozilla
1Firefox
Jun 17, 2026
Jun 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This...Show more
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dangerous if the local files came from different sources, such as in a download directory. This vulnerability affects Firefox < 111.Show less
1Supremainc
1Biostar 2
Jun 17, 2026
May 22, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The v...Show more
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full administrator privileges on the system.Show less
1Thecontrolgroup
1Voyager
Jun 17, 2026
Apr 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
1Liferay
1Liferay Portal
Jun 17, 2026
Apr 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessi...Show more
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.Show less
1Trellix
1Agent
Jun 17, 2026
Apr 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows t...Show more
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions. Show less