VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 75 of 79
  • CVE-2022-31072LowJun 15, 2022
    risk 0.09cvss 2.5epss 0.00

    Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644).…

  • CVE-2022-31071LowJun 15, 2022
    risk 0.09cvss 2.5epss 0.00

    Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This…

  • CVE-2025-61970LowAug 11, 2026
    risk 0.07cvss epss 0.00

    Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.

  • CVE-2025-48505LowAug 11, 2026
    risk 0.07cvss epss 0.00

    Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code execution.

  • CVE-2019-15793MedApr 24, 2020
    risk 0.03cvss 6.5epss 0.01

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should…

  • CVE-2015-7985Nov 24, 2015
    risk 0.03cvss epss 0.01

    Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.

  • CVE-2026-4793HigAug 3, 2026
    risk 0.00cvss 7.3epss 0.00

    An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

  • CVE-2026-39874HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

  • CVE-2026-17497HigJul 26, 2026
    risk 0.00cvss 8.3epss 0.00

    NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run…

  • CVE-2026-16247HigJul 20, 2026
    risk 0.00cvss 7.3epss 0.00

    In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to…

  • CVE-2026-16246HigJul 20, 2026
    risk 0.00cvss 7.3epss 0.00

    In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. Starting with BRAIN2 3.09, the…

  • CVE-2026-40952HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a…

  • CVE-2026-61828HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI…

  • CVE-2025-27464CriJul 9, 2026
    risk 0.00cvss epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to…

  • CVE-2025-27463CriJul 9, 2026
    risk 0.00cvss epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to…

  • CVE-2025-27462CriJul 9, 2026
    risk 0.00cvss epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to…

  • CVE-2026-57895HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folder, which results in arbitrary code execution with SYSTEM privilege

  • CVE-2026-57919HigJun 29, 2026
    risk 0.00cvss 7.8epss 0.00

    PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted…

  • CVE-2026-57924MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

  • CVE-2026-12602HigJun 22, 2026
    risk 0.00cvss epss 0.00

    Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program…