VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 15 of 80
  • CVE-2026-49237HigMay 28, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img,…

  • CVE-2026-44469HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with…

  • CVE-2026-44468HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the…

  • CVE-2026-45393HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorrect default permissions on the Windows installer's authentication directory (CWE-276) expose a cryptographic secret used for JWT…

  • CVE-2026-39454HigApr 20, 2026
    risk 0.51cvss 7.8epss 0.00

    SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result,…

  • CVE-2026-25203HigApr 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.

  • CVE-2026-32680HigMar 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It…

  • CVE-2026-3315HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.

  • CVE-2026-26131HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2026-28727HigMar 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.

  • CVE-2026-26034HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.

  • CVE-2026-23703HigFeb 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.

  • CVE-2025-1789HigFeb 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

  • CVE-2026-25931HigFeb 9, 2026
    risk 0.51cvss 7.8epss 0.00

    vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is…

  • CVE-2025-69604HigJan 29, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

  • CVE-2021-47761HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when…

  • CVE-2025-53919HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local access could potentially exploit this,…

  • CVE-2025-53398HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

  • CVE-2025-13155HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2025-61229HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.