VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 15 of 79
  • CVE-2026-26034HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.

  • CVE-2026-23703HigFeb 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.

  • CVE-2025-1789HigFeb 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

  • CVE-2026-25931HigFeb 9, 2026
    risk 0.51cvss 7.8epss 0.00

    vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is…

  • CVE-2025-69604HigJan 29, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

  • CVE-2021-47761HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when…

  • CVE-2025-53919HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local access could potentially exploit this,…

  • CVE-2025-53398HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

  • CVE-2025-13155HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2025-61229HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

  • CVE-2025-58097HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.

  • CVE-2025-34333HigNov 19, 2025
    risk 0.51cvss 7.8epss 0.00

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated…

  • CVE-2025-34332HigNov 19, 2025
    risk 0.51cvss 7.8epss 0.00

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain…

  • CVE-2025-13131HigNov 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with…

  • CVE-2025-13130HigNov 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Service. Such manipulation leads to incorrect default permissions. The attack can only be performed from a…

  • CVE-2025-23347HigOct 23, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

  • CVE-2025-11575HigOct 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.

  • CVE-2025-23297HigOct 1, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of…

  • CVE-2025-43725HigSep 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2025-57846HigAug 27, 2025
    risk 0.51cvss 7.8epss 0.00

    Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacker may replace a service executable on the system where the product is running, potentially allowing arbitrary code execution…