← Back
CWE-281

339 CVEs • Abstraction: Base

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

JSON object

Loading...

CVEs (339)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Dec 18, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.
1Apple
6Ipados
Iphone OsMacos+3 more
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access sensitive user data...Show more
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access sensitive user data.Show less
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controlle...Show more
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.Show less
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the c...Show more
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.Show less
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.
-
-
Jun 17, 2026
Dec 4, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.miste...Show more
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity component.Show less
-
-
Jun 17, 2026
Nov 26, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating...Show more
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that user will inherit all of the previous user's credentials. This issue has been addressed in release version 1.33.0 and all users are advised to upgrade. The only known workaround for those who cannot upgrade is to not reuse usernames.Show less