CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,581)
page 33 of 80| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18868 | Hig | 0.50 | 7.7 | 0.01 | May 21, 2020 | Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built. | ||
| CVE-2025-68825 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications. | ||
| CVE-2025-59030 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2025 | An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. | ||
| CVE-2025-13025 | Hig | 0.49 | 7.5 | 0.00 | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | ||
| CVE-2025-54530 | Hig | 0.49 | 7.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | ||
| CVE-2025-30706 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2025 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | ||
| CVE-2024-55950 | Hig | 0.49 | — | 0.00 | Dec 26, 2024 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential security vulnerabilities. The application… | ||
| CVE-2024-49202 | Hig | 0.49 | 7.6 | 0.00 | Dec 18, 2024 | Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0. | ||
| CVE-2024-44786 | Hig | 0.49 | 7.5 | 0.01 | Nov 22, 2024 | Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors. | ||
| CVE-2024-28058 | Hig | 0.49 | 7.5 | 0.00 | Nov 18, 2024 | In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data. | ||
| CVE-2024-36063 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2024 | The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component. | ||
| CVE-2024-44228 | Hig | 0.49 | 7.5 | 0.00 | Oct 28, 2024 | This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data. | ||
| CVE-2024-44100 | Hig | 0.49 | 7.5 | 0.00 | Oct 25, 2024 | Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545. | ||
| CVE-2024-44760 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2024 | Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server. | ||
| CVE-2024-43114 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2024 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | ||
| CVE-2023-38370 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197. | ||
| CVE-2024-37038 | Hig | 0.49 | 7.5 | 0.00 | Jun 12, 2024 | CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests. | ||
| CVE-2023-23976 | Hig | 0.49 | 7.5 | 0.00 | Apr 24, 2024 | Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2. | ||
| CVE-2023-52545 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-22889 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2024 | Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request. |
- risk 0.50cvss 7.7epss 0.01
Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built.
- risk 0.49cvss 7.5epss 0.00
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.
- risk 0.49cvss 7.5epss 0.01
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
- risk 0.49cvss 7.5epss 0.00
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
- risk 0.49cvss —epss 0.00
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential security vulnerabilities. The application…
- risk 0.49cvss 7.6epss 0.00
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.
- risk 0.49cvss 7.5epss 0.00
In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.
- risk 0.49cvss 7.5epss 0.00
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component.
- risk 0.49cvss 7.5epss 0.00
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
- risk 0.49cvss 7.5epss 0.00
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
- risk 0.49cvss 7.5epss 0.01
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
- risk 0.49cvss 7.5epss 0.00
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
- risk 0.49cvss 7.5epss 0.00
Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.01
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.