CWE-281
337 CVEs • Abstraction: Base
Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 11Nuc7i3dnbe Firmware Nuc7i3dnhe FirmwareNuc7i3dnhnc Firmware+8 moreJun 17, 2026 Nov 11, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local...Show more |
A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder. This directory listing provides an at...Show more |
2Fedoraproject Opendev3Fedora Sushy ToolsVirtualbmcJun 17, 2026 Oct 30, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NO...Show more |
1Verint 1Desktop And Process Analytics Jun 17, 2026 Oct 20, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair. |
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate perm...Show more |
1Redhat 2Decision Manager Process AutomationJun 17, 2026 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console. |
Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some fol...Show more |
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators. |
Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not ab...Show more |
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session. |
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerab...Show more |
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnera...Show more |
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunic...Show more |
1Ibm 1Spectrum Protect Plus Container Backup And Restore Jun 17, 2026 Jun 30, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role b...Show more |
MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Res...Show more |
Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does not adhere to the email domain restricti...Show more |
1Qualcomm 61Apq8053 Firmware Aqt1000 FirmwareMsm8953 Firmware+58 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indust...Show more |
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. |
1Eginnovations 4Eg Agent Eg ManagerEg Rum Collectors+1 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. |
4Fedoraproject Podman ProjectPsgo Project+1 more16Developer Tools Enterprise LinuxEnterprise Linux Eus+13 moreJun 17, 2026 Apr 29, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a...Show more |