← Back
CWE-281

337 CVEs • Abstraction: Base

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

JSON object

Loading...

CVEs (337)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Firefox
Jun 17, 2026
Feb 26, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affect...Show more
When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.Show less
1Pimcore
1Pimcore
Jun 17, 2026
Dec 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.
1Nagios
1Nagios Xi
Jun 17, 2026
Nov 13, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrar...Show more
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.Show less
1Intel
1Data Center Manager
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access.
1Intel
1Data Center Manager
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Processor Identification Utility
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for the Intel(R) Processor Identification Utility before version 6.4.0603 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Advisor Tools
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for the Intel(R) Advisor tools before version 2020 Update 2 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Hid Event Filter Driver
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for the Intel(R) HID Event Filter Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Falcon 8+ Uas Asctec Thermal Viewer Firmware
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Oct 16, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI...Show more
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.</p> <p>The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.</p>Show less
1Nextcloud
1Deck
Jun 17, 2026
Oct 5, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
4Debian
FedoraprojectGoogle+1 more
5Backports Sle
ChromeDebian Linux+2 more
Jun 17, 2026
Sep 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
1Google
1Android
Jun 17, 2026
Sep 18, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not nee...Show more
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 15, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 fac...Show more
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.Show less
2Apache
Oracle
5Communications Policy Management
Financial Services Data Integration HubFinancial Services Market Risk Measurement And Management+2 more
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 13, 2020
N/A· v4
3.5 LOW· v3
4.9 MEDIUM· v2
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
1Android
1Play Core Library
Jun 17, 2026
Aug 12, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific applica...Show more
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.Show less
2Etcd
Fedoraproject
2Etcd
Fedora
Jun 17, 2026
Aug 5, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients...Show more
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).Show less
1Citrix
3Application Delivery Controller Firmware
Gateway FirmwareNetscaler Gateway Firmware
Jun 17, 2026
Jul 10, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
1Gogs
1Gogs
Jun 17, 2026
Jun 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.