CWE-277
Insecure Inherited Permissions
Description
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (74)
page 1 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36540 | Cri | 0.64 | 9.8 | 0.00 | Jul 24, 2024 | Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | ||
| CVE-2024-36539 | Cri | 0.64 | 9.8 | 0.01 | Jul 24, 2024 | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | ||
| CVE-2026-7891 | Cri | 0.59 | 9.1 | 0.00 | May 7, 2026 | A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This… | ||
| CVE-2024-36542 | Hig | 0.57 | 8.8 | 0.00 | Jul 25, 2024 | Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | ||
| CVE-2024-6605 | Hig | 0.57 | 8.8 | 0.00 | Jul 9, 2024 | Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128. | ||
| CVE-2023-27842 | Hig | 0.57 | 8.8 | 0.02 | Mar 21, 2023 | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent | ||
| CVE-2021-41170 | Cri | 0.57 | 9.8 | 0.02 | Nov 8, 2021 | neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a… | ||
| CVE-2016-6811 | Hig | 0.57 | 8.8 | 0.03 | Apr 11, 2017 | In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user. | ||
| CVE-2024-34329 | Hig | 0.55 | 8.4 | 0.01 | Jul 22, 2024 | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload. | ||
| CVE-2024-29417 | Hig | 0.55 | 8.4 | 0.00 | May 3, 2024 | Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function. | ||
| CVE-2024-7143 | Hig | 0.54 | 8.3 | 0.01 | Aug 7, 2024 | A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the… | ||
| CVE-2026-30266 | Hig | 0.51 | 7.8 | 0.00 | Apr 20, 2026 | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file | ||
| CVE-2024-27848 | Hig | 0.51 | 7.8 | 0.00 | Jun 10, 2024 | This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges. | ||
| CVE-2024-27822 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges. | ||
| CVE-2024-23233 | Hig | 0.51 | 7.8 | 0.00 | Mar 8, 2024 | This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app. | ||
| CVE-2023-33990 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an… | ||
| CVE-2025-20008 | Hig | 0.50 | 7.7 | 0.00 | May 13, 2025 | Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2024-42681 | Hig | 0.50 | 8.8 | 0.01 | Aug 15, 2024 | Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component. | ||
| CVE-2024-39877 | Hig | 0.50 | 8.8 | 0.02 | Jul 17, 2024 | Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users… | ||
| CVE-2024-41601 | Hig | 0.49 | 7.5 | 0.00 | Jul 19, 2024 | Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component. |
- risk 0.64cvss 9.8epss 0.00
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- risk 0.64cvss 9.8epss 0.01
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- risk 0.59cvss 9.1epss 0.00
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This…
- risk 0.57cvss 8.8epss 0.00
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- risk 0.57cvss 8.8epss 0.00
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
- risk 0.57cvss 8.8epss 0.02
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent
- risk 0.57cvss 9.8epss 0.02
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a…
- risk 0.57cvss 8.8epss 0.03
In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
- risk 0.55cvss 8.4epss 0.01
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.
- risk 0.55cvss 8.4epss 0.00
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.
- risk 0.54cvss 8.3epss 0.01
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the…
- risk 0.51cvss 7.8epss 0.00
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file
- risk 0.51cvss 7.8epss 0.00
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.
- risk 0.51cvss 7.8epss 0.01
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.
- risk 0.51cvss 7.8epss 0.00
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
- risk 0.51cvss 7.8epss 0.00
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an…
- risk 0.50cvss 7.7epss 0.00
Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.50cvss 8.8epss 0.01
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
- risk 0.50cvss 8.8epss 0.02
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users…
- risk 0.49cvss 7.5epss 0.00
Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.