CWE-276: CWE-276

426
Total CVEs
59
Critical
273
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Amd 6
7 Oracle 5
8 Ivanti 5
9 Juniper 5
10 Debian 4

All CWE-276 CVEs (426)

CVE-2023-24460
8.2

This vulnerability allows authenticated users on a local system to escalate privileges due to incorrect default permissions in Intel GPA software inst...

May 16, 2024
CVE-2024-20005
8.2

This vulnerability allows local privilege escalation on MediaTek devices due to a missing permission check in the 'da' component. Attackers can gain S...

Mar 4, 2024
CVE-2021-44905
8.2

CVE-2021-44905 is an incorrect permissions vulnerability in Fortessa FTBTLD Smart Lock's Bluetooth services that allows remote attackers to disable th...

Mar 25, 2022
CVE-2024-52867
8.1

This vulnerability in GNU Guix's guix-daemon allows local users to escalate privileges by accessing build outputs before proper file metadata (like se...

Nov 17, 2024
CVE-2024-7525
8.1

This vulnerability allows web extensions with minimal permissions to intercept and modify HTTP responses for any website, bypassing normal security re...

Aug 6, 2024
CVE-2022-25364
8.1

Gradle Enterprise versions before 2021.4.2 had a default configuration allowing anonymous write access to the built-in build cache. This could allow a...

Mar 17, 2022
CVE-2024-1488
8.0

This CVE allows any local process to modify Unbound DNS resolver's runtime configuration via port 8953 due to incorrect default permissions. Attackers...

Feb 15, 2024
CVE-2023-45990
8.0

CVE-2023-45990 is an insecure permissions vulnerability in WenwenaiCMS v1.0 that allows remote attackers to escalate privileges. This affects all depl...

Oct 25, 2023
CVE-2024-21840
7.9

This vulnerability allows local users on the VMware vCenter server to read and write specific files due to incorrect default permissions in the Hitach...

Jan 30, 2024
CVE-2026-28727
7.8

This vulnerability allows local attackers to escalate privileges on macOS systems by exploiting insecure Unix socket permissions in Acronis Cyber Prot...

Mar 6, 2026
CVE-2026-26034
7.8

CVE-2026-26034 is an incorrect default permissions vulnerability in Dell UPS Multi-UPS Management Console (MUMC) that allows attackers to execute arbi...

Mar 5, 2026
CVE-2026-23703
7.8

The installer for FinalCode Client by Digital Arts Inc. has incorrect default permissions that allow non-administrative users to execute arbitrary cod...

Feb 26, 2026
CVE-2025-1789
7.8

This vulnerability allows authenticated low-privileged Windows users to escalate their privileges on systems running Genetec Update Service. Attackers...

Feb 24, 2026
CVE-2026-25931
7.8

This vulnerability in vscode-spell-checker extension allows arbitrary code execution when opening untrusted VS Code workspaces. Attackers can place ma...

Feb 9, 2026
CVE-2025-69604
7.8

This vulnerability in SuperDuper! backup software allows local attackers to modify task templates to install arbitrary packages with root privileges a...

Jan 29, 2026
CVE-2021-47761
7.8

MilleGPG5 5.7.2 contains a local privilege escalation vulnerability where authenticated users can modify MariaDB service executable files. Attackers c...

Jan 15, 2026
CVE-2025-53398
7.8

CVE-2025-53398 is an insecure permissions vulnerability in Portrait Dell Color Management application 3.3.8 for Dell monitors that allows unauthorized...

Dec 17, 2025
CVE-2025-53919
7.8

The Portrait Dell Color Management application creates a temporary folder with weak permissions during installation/uninstallation, allowing local low...

Dec 17, 2025
CVE-2025-13155
7.8

An improper permissions vulnerability in Lenovo Baiying Client allows local authenticated users to execute arbitrary code with elevated privileges. Th...

Dec 10, 2025
CVE-2025-61229
7.8

A local privilege escalation vulnerability in SuperDuper! backup software allows attackers to modify task templates and execute arbitrary scripts with...

Dec 1, 2025
CVE-2025-58097
7.8

LogStare Collector's installation directory has insecure permissions allowing non-admin users to modify files. This enables privilege escalation where...

Nov 21, 2025
CVE-2025-34332
7.8

This vulnerability allows any authenticated local user on AudioCodes Fax Server and Auto-Attendant IVR appliances to escalate privileges to SYSTEM by ...

Nov 19, 2025
CVE-2025-34333
7.8

This vulnerability allows any authenticated local user on AudioCodes Fax Server and Auto-Attendant IVR appliances to achieve privilege escalation to S...

Nov 19, 2025
CVE-2025-12100
7.8

The MongoDB BI Connector ODBC driver versions 1.0.0 through 1.4.6 have incorrect default permissions that allow local users to escalate privileges. Th...

Oct 23, 2025
CVE-2025-23347
7.8

NVIDIA Project G-Assist contains an incorrect default permissions vulnerability (CWE-276) that allows attackers to escalate privileges. This affects s...

Oct 23, 2025
CVE-2025-11575
7.8

The MongoDB Atlas SQL ODBC driver on Windows has incorrect default permissions that allow local users to escalate privileges. This affects all Windows...

Oct 23, 2025
CVE-2025-23297
7.8

This vulnerability in NVIDIA's FrameviewSDK installer for Windows allows local unprivileged attackers to modify files in the Frameview SDK directory, ...

Oct 1, 2025
CVE-2025-43725
7.8

Dell PowerProtect Data Manager Generic Application Agent versions 19.19 and 19.20 have incorrect default permissions that allow local low-privileged a...

Sep 10, 2025
CVE-2025-57846
7.8

Multiple i-フィルター products have incorrect default permissions that allow local authenticated attackers to replace service executables. This c...

Aug 27, 2025
CVE-2025-8672
7.8

This vulnerability allows local attackers on macOS to abuse GIMP's bundled Python interpreter to access privacy-protected files without user consent. ...

Aug 11, 2025
CVE-2025-8069
7.8

This vulnerability allows non-admin Windows users to execute arbitrary code with administrator privileges during AWS Client VPN installation. Attacker...

Jul 23, 2025
CVE-2025-0886
7.8

An incorrect permissions vulnerability in Elliptic Labs Virtual Lock Sensor allows local authenticated users to escalate privileges. This affects syst...

Jul 17, 2025
CVE-2025-43596
7.8

An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows low-privileged users to execute arbitrary commands with SYSTEM privilege...

May 22, 2025
CVE-2025-42598
7.8

This vulnerability allows attackers to execute arbitrary code with SYSTEM privileges on Windows systems by placing a crafted DLL file in a specific lo...

Apr 28, 2025
CVE-2025-24914
7.8

This vulnerability allows local privilege escalation on Windows systems where Nessus is installed to a non-default location. Attackers could exploit i...

Apr 18, 2025
CVE-2025-3617
7.8

A privilege escalation vulnerability in Rockwell Automation ThinManager allows attackers to inherit elevated permissions when temporary files are dele...

Apr 15, 2025
CVE-2025-23386
7.8

This vulnerability allows the gerbera service user to escalate privileges to root due to incorrect default permissions in openSUSE Tumbleweed. It affe...

Apr 10, 2025
CVE-2025-29504
7.8

This CVE describes an insecure permission verification vulnerability in student-manage 1 that allows local attackers to escalate privileges. Attackers...

Apr 3, 2025
CVE-2025-24277
7.8

A directory path parsing vulnerability in macOS allows applications to bypass path validation and gain root privileges. This affects macOS Ventura, Se...

Mar 31, 2025
CVE-2025-24267
7.8

A permissions vulnerability in macOS allows malicious applications to escalate privileges to root access. This affects macOS Ventura, Sequoia, and Son...

Mar 31, 2025
CVE-2025-24234
7.8

A privilege escalation vulnerability in macOS allows malicious applications to gain root privileges. This affects macOS Ventura, Sequoia, and Sonoma s...

Mar 31, 2025
CVE-2025-24915
7.8

This vulnerability allows local privilege escalation on Windows systems where Nessus Agent was installed to a non-default location with insecure direc...

Mar 21, 2025
CVE-2025-22447
7.8

This vulnerability allows non-administrative users on a Windows system running RemoteView Agent to execute arbitrary operating system commands with Lo...

Mar 6, 2025
CVE-2025-24864
7.8

CVE-2025-24864 is a privilege escalation vulnerability in RemoteView Agent for Windows where incorrect folder permissions allow non-administrative use...

Mar 6, 2025
CVE-2024-51440
7.8

This vulnerability in Nothing OS allows a local attacker to escalate privileges through the NtBpfService component. It affects users of Nothing Tech d...

Feb 12, 2025
CVE-2024-11468
7.8

A local privilege escalation vulnerability in Omnissa Horizon Client for macOS allows authenticated users to gain root privileges on affected systems....

Feb 4, 2025
CVE-2025-24135
7.8

A privilege escalation vulnerability in macOS allows malicious applications to gain elevated system privileges. This affects macOS systems before Sequ...

Jan 27, 2025
CVE-2025-24107
7.8

A permissions vulnerability in Apple operating systems allows malicious applications to escalate privileges to root access. This affects macOS, tvOS, ...

Jan 27, 2025
CVE-2025-0543
7.8

CVE-2025-0543 is a local privilege escalation vulnerability in G DATA Security Client where incorrect directory permissions allow unprivileged local u...

Jan 25, 2025
CVE-2024-55957
7.8

This CVE describes a local privilege escalation vulnerability in Thermo Fisher Scientific Xcalibur and Foundation Instrument Control Software on Windo...

Jan 22, 2025

About CWE-276 (CWE-276)

Our database tracks 426 CVEs classified as CWE-276, with 59 rated critical and 273 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free