← Back
CWE-281

339 CVEs • Abstraction: Base

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

JSON object

Loading...

CVEs (339)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Katacontainers
1Kata Containers
Jul 15, 2026
Feb 19, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allo...Show more
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately achieving arbitrary code execution as root in said VM. The current understanding is this doesn’t impact the security of the Host or of other containers / VMs running on that Host (note that arm64 QEMU lacks NVDIMM read-only support: It is believed that until the upstream QEMU gains this capability, a guest write could reach the image file). Version 3.27.0 patches the issue.Show less
1Quickheal
1Total Security
Jun 17, 2026
Feb 3, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to resto...Show more
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.Show less
-
-
Jun 30, 2026
Jan 26, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root priv...Show more
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.Show less
1Nodejs
1Node.js
Jul 15, 2026
Jan 20, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access o...Show more
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.Show less
-
-
Jun 17, 2026
Nov 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modif...Show more
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.Show less
-
-
Jun 17, 2026
Nov 6, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege...Show more
Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.Show less
1Nagios
1Log Server
Jun 17, 2026
Oct 30, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation a...Show more
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.Show less
-
-
Jun 17, 2026
Oct 29, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only...Show more
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLsShow less
1Google
1Android
Jun 17, 2026
Sep 4, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with...Show more
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
-
-
Jun 17, 2026
Jul 8, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
-
-
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impacts OmniStudio: before version 254.
-
-
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.  This impacts OmniStudio: before Spring 2025.
-
-
Jun 17, 2026
Jun 10, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025
-
-
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025
1Openatom
1Openharmony
Jun 17, 2026
Jun 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
1Openatom
1Openharmony
Jun 17, 2026
Jun 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
1Openatom
1Openharmony
Jun 17, 2026
Jun 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
1Openatom
1Openharmony
Jun 17, 2026
Jun 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
-
-
Jun 17, 2026
Jun 6, 2025
4.8 MEDIUM· v4
N/A· v3
N/A· v2
SystemUI has an incorrect component protection setting, which allows access to specific information.
1Hp
1Support Assistant
Jun 17, 2026
Jun 5, 2025
7.1 HIGH· v4
7.8 HIGH· v3
N/A· v2
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file...Show more
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.Show less