VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 6 of 79
  • CVE-2021-44140CriNov 24, 2021
    risk 0.60cvss 9.1epss 0.06

    Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to…

  • CVE-2017-11741HigAug 8, 2017
    risk 0.60cvss 8.8epss 0.01

    HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.

  • CVE-2025-49084CriJul 31, 2025
    risk 0.59cvss 9.1epss 0.00

    CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requirements are present,…

  • CVE-2024-57548CriJan 27, 2025
    risk 0.59cvss 9.1epss 0.00

    CMSimple 5.16 allows the user to edit log.php file via print page.

  • CVE-2024-55959CriJan 21, 2025
    risk 0.59cvss 9.1epss 0.01

    Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.

  • CVE-2024-46505CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

  • CVE-2019-20457CriNov 7, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorization cookie. The value of the…

  • CVE-2024-30415CriApr 7, 2024
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-41943CriNov 22, 2022
    risk 0.59cvss 9.0epss 0.01

    sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version…

  • CVE-2022-34737CriJul 12, 2022
    risk 0.59cvss 9.1epss 0.01

    The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.

  • CVE-2021-40053CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.01

    There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.

  • CVE-2021-39635CriFeb 11, 2022
    risk 0.59cvss 9.1epss 0.01

    ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2021-31217CriJul 13, 2021
    risk 0.59cvss 9.1epss 0.04

    In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

  • CVE-2022-22948MedKEVMar 29, 2022
    risk 0.58cvss 6.5epss 0.14

    The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

  • CVE-2020-28906HigMay 24, 2021
    risk 0.58cvss 8.8epss 0.05

    Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

  • CVE-2020-11444HigApr 2, 2020
    risk 0.58cvss 8.8epss 0.09

    Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

  • CVE-2017-8625HigAug 8, 2017
    risk 0.58cvss 8.8epss 0.15

    Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass…

  • CVE-2026-49157HigJun 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which…

  • CVE-2026-21765HigApr 2, 2026
    risk 0.57cvss 8.8epss 0.00

    HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

  • CVE-2025-10314HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing service executable files (EXE) or DLLs in the installation…