VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 74 of 79
  • CVE-2019-10473MedOct 23, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2026-27680LowMay 14, 2026
    risk 0.20cvss 3.1epss 0.00

    Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is…

  • CVE-2023-23344LowJun 23, 2023
    risk 0.20cvss 3.0epss 0.00

    A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

  • CVE-2024-47825MedOct 21, 2024
    risk 0.19cvss 4.0epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than `/32` may be ignored if there is a policy rule referencing a more…

  • CVE-2025-49082LowJul 31, 2025
    risk 0.18cvss 2.7epss 0.00

    CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other…

  • CVE-2025-1699LowJun 11, 2025
    risk 0.18cvss 2.8epss 0.00

    An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.

  • CVE-2024-53921LowDec 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

  • CVE-2024-30204LowMar 25, 2024
    risk 0.18cvss 2.8epss 0.00

    In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

  • CVE-2020-11692LowApr 22, 2020
    risk 0.18cvss 2.7epss 0.01

    In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.

  • CVE-2021-39886LowOct 5, 2021
    risk 0.17cvss 2.6epss 0.01

    Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

  • CVE-2025-43350LowNov 4, 2025
    risk 0.16cvss 2.4epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.

  • CVE-2024-21004LowApr 16, 2024
    risk 0.16cvss 2.5epss 0.00

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability…

  • CVE-2024-21002LowApr 16, 2024
    risk 0.16cvss 2.5epss 0.00

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability…

  • CVE-2023-21512LowJun 28, 2023
    risk 0.16cvss 2.4epss 0.00

    Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.

  • CVE-2019-8777LowOct 27, 2020
    risk 0.16cvss 2.4epss 0.00

    A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. A local attacker may be able to view…

  • CVE-2024-21123LowJul 16, 2024
    risk 0.15cvss 2.3epss 0.00

    Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database…

  • CVE-2025-55074LowNov 18, 2025
    risk 0.13cvss 3.0epss 0.00

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

  • CVE-2025-49843LowJun 17, 2025
    risk 0.11cvss epss 0.01

    conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_headers function in the conda-smithy repository creates files with permissions exceeding 0o600, allowing…

  • CVE-2024-5967LowJun 18, 2024
    risk 0.11cvss 2.7epss 0.01

    A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL  independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permission manage-realm) to change the LDAP…

  • CVE-2019-16183LowSep 9, 2019
    risk 0.11cvss 2.7epss 0.01

    In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.