← Back
CWE-281

337 CVEs • Abstraction: Base

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

JSON object

Loading...

CVEs (337)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
11Nuc7i3dnbe Firmware
Nuc7i3dnhe FirmwareNuc7i3dnhnc Firmware+8 more
Jun 17, 2026
Nov 11, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local...Show more
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Hitachi
1Vantara Pentaho
Jun 17, 2026
Nov 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an at...Show more
A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located inside the directory. Show less
2Fedoraproject
Opendev
3Fedora
Sushy ToolsVirtualbmc
Jun 17, 2026
Oct 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NO...Show more
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."Show less
1Verint
1Desktop And Process Analytics
Jun 17, 2026
Oct 20, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.
1Relatedcode
1Messenger
Jun 17, 2026
Oct 19, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate perm...Show more
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.Show less
1Redhat
2Decision Manager
Process Automation
Jun 17, 2026
Oct 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
1Grafana
1Grafana
Jun 17, 2026
Sep 22, 2022
N/A· v4
3.8 LOW· v3
N/A· v2
Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some fol...Show more
Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.Show less
1Processmaker
1Processmaker
Jul 9, 2026
Sep 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
1Shopware
1Shopware
Jun 17, 2026
Sep 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not ab...Show more
Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current version (5.7.15). Users can get the update via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.Show less
1Debian
2Debian Linux
Schroot
Jun 17, 2026
Aug 27, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
1Redhat
1Satellite
Jun 17, 2026
Aug 26, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerab...Show more
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.Show less
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Aug 22, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnera...Show more
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure.Show less
1Gog
1Galaxy
Jun 17, 2026
Aug 17, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunic...Show more
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.Show less
1Ibm
1Spectrum Protect Plus Container Backup And Restore
Jun 17, 2026
Jun 30, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role b...Show more
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By retrieving the logs of a container an attacker could exploit this vulnerability to bypass login security of the IBM Spectrum Protect Plus server and gain unauthorized access based on the permissions of the IBM Spectrum Protect Plus user to the vulnerable Spectrum Protect Plus server software. IBM X-Force ID: 225340.Show less
1Metamask
1Metamask
Jun 17, 2026
Jun 29, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Res...Show more
MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.Show less
1Discourse
1Discourse
Jun 17, 2026
Jun 27, 2022
N/A· v4
5.7 MEDIUM· v3
2.1 LOW· v2
Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does not adhere to the email domain restricti...Show more
Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does not adhere to the email domain restriction of an invite link. The impact of this flaw is aggravated when the invite has been configured to add the user that accepts the invite into restricted groups. Once a user has been incorrectly added to a restricted group, the user may then be able to view content which that are restricted to the respective group. Users are advised to upgrade to the current stable releases. There are no known workarounds to this issue.Show less
1Qualcomm
61Apq8053 Firmware
Aqt1000 FirmwareMsm8953 Firmware+58 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indust...Show more
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon MobileShow less
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
1Eginnovations
4Eg Agent
Eg ManagerEg Rum Collectors+1 more
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
4Fedoraproject
Podman ProjectPsgo Project+1 more
16Developer Tools
Enterprise LinuxEnterprise Linux Eus+13 more
Jun 17, 2026
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a...Show more
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.Show less