VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 67 of 79
  • CVE-2026-48790MedAug 11, 2026
    risk 0.29cvss 5.5epss 0.00

    Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux…

  • CVE-2026-56301MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket without permission restrictions, allowing local users to enumerate and connect. Unprivileged co-resident…

  • CVE-2026-53870MedJun 17, 2026
    risk 0.29cvss 5.5epss 0.00

    Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain…

  • CVE-2026-53856MedJun 16, 2026
    risk 0.29cvss 5.5epss 0.00

    OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can read sensitive configuration data by exploiting the recovery path to access…

  • CVE-2025-52900MedJun 26, 2025
    risk 0.29cvss 5.5epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by the application. The same…

  • CVE-2025-6264MedJun 20, 2025
    risk 0.29cvss 5.5epss 0.01

    Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions.  To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions…

  • CVE-2024-0245MedMar 20, 2025
    risk 0.29cvss 5.5epss 0.00

    A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permissions of the vulnerable app, potentially leading to the exposure of sensitive information. An…

  • CVE-2023-52954MedJan 8, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-22385MedJun 25, 2024
    risk 0.29cvss 4.4epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.

  • CVE-2024-34012MedJun 14, 2024
    risk 0.29cvss 4.4epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

  • CVE-2024-29967MedApr 19, 2024
    risk 0.29cvss 4.4epss 0.00

    In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read…

  • CVE-2024-0770MedJan 21, 2024
    risk 0.29cvss 4.4epss 0.00

    A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file iuclid6.exe of the component Desktop Installer. The manipulation leads to incorrect default permissions. The attack…

  • CVE-2023-27392MedAug 11, 2023
    risk 0.29cvss 4.4epss 0.00

    Incorrect default permissions in the Intel(R) Support android application before version v23.02.07 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-36367MedNov 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2021-3917MedAug 23, 2022
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to…

  • CVE-2022-0486MedMay 17, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The…

  • CVE-2022-27840MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.

  • CVE-2022-25327MedFeb 25, 2022
    risk 0.29cvss 5.5epss 0.00

    The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users…

  • CVE-2021-0093MedFeb 9, 2022
    risk 0.29cvss 4.4epss 0.00

    Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

  • CVE-2020-4976MedMar 11, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.