CWE-276: CWE-276
Yearly Trend
Top Affected Vendors
All CWE-276 CVEs (426)
This vulnerability allows authenticated users on a local system to escalate privileges due to incorrect default permissions in Intel GPA software inst...
May 16, 2024This vulnerability allows local privilege escalation on MediaTek devices due to a missing permission check in the 'da' component. Attackers can gain S...
Mar 4, 2024CVE-2021-44905 is an incorrect permissions vulnerability in Fortessa FTBTLD Smart Lock's Bluetooth services that allows remote attackers to disable th...
Mar 25, 2022This vulnerability in GNU Guix's guix-daemon allows local users to escalate privileges by accessing build outputs before proper file metadata (like se...
Nov 17, 2024This vulnerability allows web extensions with minimal permissions to intercept and modify HTTP responses for any website, bypassing normal security re...
Aug 6, 2024Gradle Enterprise versions before 2021.4.2 had a default configuration allowing anonymous write access to the built-in build cache. This could allow a...
Mar 17, 2022This CVE allows any local process to modify Unbound DNS resolver's runtime configuration via port 8953 due to incorrect default permissions. Attackers...
Feb 15, 2024CVE-2023-45990 is an insecure permissions vulnerability in WenwenaiCMS v1.0 that allows remote attackers to escalate privileges. This affects all depl...
Oct 25, 2023This vulnerability allows local users on the VMware vCenter server to read and write specific files due to incorrect default permissions in the Hitach...
Jan 30, 2024This vulnerability allows local attackers to escalate privileges on macOS systems by exploiting insecure Unix socket permissions in Acronis Cyber Prot...
Mar 6, 2026CVE-2026-26034 is an incorrect default permissions vulnerability in Dell UPS Multi-UPS Management Console (MUMC) that allows attackers to execute arbi...
Mar 5, 2026The installer for FinalCode Client by Digital Arts Inc. has incorrect default permissions that allow non-administrative users to execute arbitrary cod...
Feb 26, 2026This vulnerability allows authenticated low-privileged Windows users to escalate their privileges on systems running Genetec Update Service. Attackers...
Feb 24, 2026This vulnerability in vscode-spell-checker extension allows arbitrary code execution when opening untrusted VS Code workspaces. Attackers can place ma...
Feb 9, 2026This vulnerability in SuperDuper! backup software allows local attackers to modify task templates to install arbitrary packages with root privileges a...
Jan 29, 2026MilleGPG5 5.7.2 contains a local privilege escalation vulnerability where authenticated users can modify MariaDB service executable files. Attackers c...
Jan 15, 2026CVE-2025-53398 is an insecure permissions vulnerability in Portrait Dell Color Management application 3.3.8 for Dell monitors that allows unauthorized...
Dec 17, 2025The Portrait Dell Color Management application creates a temporary folder with weak permissions during installation/uninstallation, allowing local low...
Dec 17, 2025An improper permissions vulnerability in Lenovo Baiying Client allows local authenticated users to execute arbitrary code with elevated privileges. Th...
Dec 10, 2025A local privilege escalation vulnerability in SuperDuper! backup software allows attackers to modify task templates and execute arbitrary scripts with...
Dec 1, 2025LogStare Collector's installation directory has insecure permissions allowing non-admin users to modify files. This enables privilege escalation where...
Nov 21, 2025This vulnerability allows any authenticated local user on AudioCodes Fax Server and Auto-Attendant IVR appliances to escalate privileges to SYSTEM by ...
Nov 19, 2025This vulnerability allows any authenticated local user on AudioCodes Fax Server and Auto-Attendant IVR appliances to achieve privilege escalation to S...
Nov 19, 2025The MongoDB BI Connector ODBC driver versions 1.0.0 through 1.4.6 have incorrect default permissions that allow local users to escalate privileges. Th...
Oct 23, 2025NVIDIA Project G-Assist contains an incorrect default permissions vulnerability (CWE-276) that allows attackers to escalate privileges. This affects s...
Oct 23, 2025The MongoDB Atlas SQL ODBC driver on Windows has incorrect default permissions that allow local users to escalate privileges. This affects all Windows...
Oct 23, 2025This vulnerability in NVIDIA's FrameviewSDK installer for Windows allows local unprivileged attackers to modify files in the Frameview SDK directory, ...
Oct 1, 2025Dell PowerProtect Data Manager Generic Application Agent versions 19.19 and 19.20 have incorrect default permissions that allow local low-privileged a...
Sep 10, 2025Multiple i-フィルター products have incorrect default permissions that allow local authenticated attackers to replace service executables. This c...
Aug 27, 2025This vulnerability allows local attackers on macOS to abuse GIMP's bundled Python interpreter to access privacy-protected files without user consent. ...
Aug 11, 2025This vulnerability allows non-admin Windows users to execute arbitrary code with administrator privileges during AWS Client VPN installation. Attacker...
Jul 23, 2025An incorrect permissions vulnerability in Elliptic Labs Virtual Lock Sensor allows local authenticated users to escalate privileges. This affects syst...
Jul 17, 2025An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows low-privileged users to execute arbitrary commands with SYSTEM privilege...
May 22, 2025This vulnerability allows attackers to execute arbitrary code with SYSTEM privileges on Windows systems by placing a crafted DLL file in a specific lo...
Apr 28, 2025This vulnerability allows local privilege escalation on Windows systems where Nessus is installed to a non-default location. Attackers could exploit i...
Apr 18, 2025A privilege escalation vulnerability in Rockwell Automation ThinManager allows attackers to inherit elevated permissions when temporary files are dele...
Apr 15, 2025This vulnerability allows the gerbera service user to escalate privileges to root due to incorrect default permissions in openSUSE Tumbleweed. It affe...
Apr 10, 2025This CVE describes an insecure permission verification vulnerability in student-manage 1 that allows local attackers to escalate privileges. Attackers...
Apr 3, 2025A directory path parsing vulnerability in macOS allows applications to bypass path validation and gain root privileges. This affects macOS Ventura, Se...
Mar 31, 2025A permissions vulnerability in macOS allows malicious applications to escalate privileges to root access. This affects macOS Ventura, Sequoia, and Son...
Mar 31, 2025A privilege escalation vulnerability in macOS allows malicious applications to gain root privileges. This affects macOS Ventura, Sequoia, and Sonoma s...
Mar 31, 2025This vulnerability allows local privilege escalation on Windows systems where Nessus Agent was installed to a non-default location with insecure direc...
Mar 21, 2025This vulnerability allows non-administrative users on a Windows system running RemoteView Agent to execute arbitrary operating system commands with Lo...
Mar 6, 2025CVE-2025-24864 is a privilege escalation vulnerability in RemoteView Agent for Windows where incorrect folder permissions allow non-administrative use...
Mar 6, 2025This vulnerability in Nothing OS allows a local attacker to escalate privileges through the NtBpfService component. It affects users of Nothing Tech d...
Feb 12, 2025A local privilege escalation vulnerability in Omnissa Horizon Client for macOS allows authenticated users to gain root privileges on affected systems....
Feb 4, 2025A privilege escalation vulnerability in macOS allows malicious applications to gain elevated system privileges. This affects macOS systems before Sequ...
Jan 27, 2025A permissions vulnerability in Apple operating systems allows malicious applications to escalate privileges to root access. This affects macOS, tvOS, ...
Jan 27, 2025CVE-2025-0543 is a local privilege escalation vulnerability in G DATA Security Client where incorrect directory permissions allow unprivileged local u...
Jan 25, 2025This CVE describes a local privilege escalation vulnerability in Thermo Fisher Scientific Xcalibur and Foundation Instrument Control Software on Windo...
Jan 22, 2025About CWE-276 (CWE-276)
Our database tracks 426 CVEs classified as CWE-276, with 59 rated critical and 273 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.
External reference: View CWE-276 on MITRE CWE →
Monitor CWE-276 Vulnerabilities
Get alerted when new CWE-276 CVEs affect your infrastructure.
Start Monitoring Free