CWE-276: CWE-276

436
Total CVEs
59
Critical
283
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Amd 6
7 Advantech 6
8 Debian 5
9 Oracle 5
10 Ivanti 5

All CWE-276 CVEs (436)

CVE-2025-20087
6.7

This vulnerability involves incorrect default permissions in Intel oneAPI DPC++/C++ Compiler installers, allowing authenticated local users to potenti...

Aug 12, 2025
CVE-2025-20023
6.7

This vulnerability involves incorrect default permissions in some Intel Graphics Driver installers, allowing authenticated local users to potentially ...

Aug 12, 2025
CVE-2025-48959
6.7

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows due to insecure file permissions. Attac...

Jun 4, 2025
CVE-2025-20095
6.7

This vulnerability in Intel RealSense SDK software allows authenticated local users to escalate privileges due to incorrect default permissions. It af...

May 13, 2025
CVE-2024-28954
6.7

This vulnerability allows authenticated local users to escalate privileges due to incorrect default permissions in Intel Graphics Driver installers. A...

May 13, 2025
CVE-2024-32942
6.7

This vulnerability in Intel DSA installer for Windows allows authenticated local users to escalate privileges due to incorrect default permissions. At...

Feb 12, 2025
CVE-2025-24826
6.7

This CVE describes a local privilege escalation vulnerability in Acronis Snap Deploy for Windows due to insecure folder permissions. Attackers with lo...

Jan 28, 2025
CVE-2024-55930
6.7

Xerox Workplace Suite has insecure default folder permissions that allow unauthorized users to access, modify, or delete files within the application'...

Jan 23, 2025
CVE-2024-29083
6.7

This vulnerability in Intel Distribution for Python allows authenticated local users to escalate privileges due to incorrect default file permissions....

Nov 13, 2024
CVE-2024-25647
6.7

This vulnerability in Intel Binary Configuration Tool for Windows allows authenticated local users to escalate privileges due to incorrect default per...

Nov 13, 2024
CVE-2024-35287
6.7

This vulnerability allows authenticated administrators in Mitel MiCollab's NuPoint Messenger component to escalate privileges and execute arbitrary co...

Oct 21, 2024
CVE-2024-23495
6.7

This vulnerability in Intel Distribution for GDB software allows authenticated local users to escalate privileges due to incorrect default permissions...

Aug 14, 2024
CVE-2023-43747
6.7

This vulnerability allows authenticated users with local access to escalate privileges due to incorrect default permissions in Intel Connectivity Perf...

Aug 14, 2024
CVE-2024-27180
6.7

This vulnerability allows attackers with administrative access to install unauthorized applications on affected Toshiba multifunction printers. It aff...

Jun 14, 2024
CVE-2023-42668
6.7

This vulnerability allows authenticated users with local access to Intel Server Boards to escalate privileges due to incorrect default permissions in ...

May 16, 2024
CVE-2025-8421
6.6

An improper default permission vulnerability in Lenovo Dock Manager allows authenticated local users to redirect log files with elevated privileges du...

Nov 12, 2025
CVE-2024-32978
6.6

Kaminari pagination library for Ruby on Rails has insecure file permissions that could allow unauthorized write access to specific Ruby files. This co...

May 27, 2024
CVE-2025-15339
6.5

CVE-2025-15339 is an incorrect default permissions vulnerability in Tanium Discover that allows unauthorized users to access sensitive information. Th...

Feb 5, 2026
CVE-2025-15340
6.5

CVE-2025-15340 is an incorrect default permissions vulnerability in Tanium Comply that allows unauthorized users to access or modify security complian...

Feb 5, 2026
CVE-2025-15341
6.5

CVE-2025-15341 is an incorrect default permissions vulnerability in Tanium Benchmark that allows unauthorized users to access sensitive configuration ...

Feb 5, 2026
CVE-2025-15343
6.5

CVE-2025-15343 is an incorrect default permissions vulnerability in Tanium Enforce that allows local users to gain elevated privileges. This affects o...

Feb 5, 2026
CVE-2025-15336
6.5

CVE-2025-15336 is an incorrect default permissions vulnerability in Tanium Performance that allows authenticated users to access or modify resources t...

Feb 5, 2026
CVE-2025-15337
6.5

CVE-2025-15337 is an incorrect default permissions vulnerability in Tanium Patch that allows unauthorized users to access or modify patch management d...

Feb 5, 2026
CVE-2025-15338
6.5

CVE-2025-15338 is an incorrect default permissions vulnerability in Tanium Partner Integration that allows unauthorized access to sensitive functional...

Feb 5, 2026
CVE-2025-43507
6.5

This CVE describes a privacy vulnerability in Apple operating systems where applications could fingerprint users by accessing sensitive data. The issu...

Nov 4, 2025
CVE-2025-41665
6.5

An attacker with low-privileged remote access can trigger a watchdog reboot on affected PLC devices due to incorrect default permissions on a configur...

Jul 8, 2025
CVE-2024-54564
6.5

This vulnerability allows files received via AirDrop to bypass macOS/iOS quarantine flagging, which normally warns users about potentially unsafe file...

Mar 21, 2025
CVE-2024-38222
6.5

This vulnerability in Microsoft Edge (Chromium-based) allows an attacker to potentially access sensitive information from the browser's memory or proc...

Sep 12, 2024
CVE-2025-57850
6.4

A container privilege escalation vulnerability in CodeReady Workspaces images allows attackers with container command execution to modify the /etc/pas...

Dec 2, 2025
CVE-2025-7195
6.4

This vulnerability allows attackers with non-root access inside affected containers to modify the /etc/passwd file due to insecure group-writable perm...

Aug 7, 2025
CVE-2025-20910
6.2

This vulnerability allows local attackers to access Galaxy Watch Gallery data due to incorrect default permissions. It affects Samsung Galaxy Watch de...

Mar 6, 2025
CVE-2024-58050
6.2

This vulnerability involves improper access permissions in Huawei's HDC module, allowing unauthorized access to sensitive service data. It affects Hua...

Mar 4, 2025
CVE-2024-35139
6.2

This vulnerability in IBM Security Access Manager Docker allows local users to access sensitive information within the container due to incorrect defa...

Jun 28, 2024
CVE-2024-5321
6.1

This CVE describes an improper permissions vulnerability in Kubernetes clusters with Windows nodes. BUILTIN\Users can read container logs and NT AUTHO...

Jul 18, 2024
CVE-2025-27612
5.9

This vulnerability in libcontainer allows tenant containers to inherit capabilities from the main container, potentially leading to privilege escalati...

Mar 21, 2025
CVE-2024-46544
5.9

This vulnerability allows local users on Unix-like systems to view and modify shared memory containing mod_jk configuration due to incorrect default p...

Sep 23, 2024
CVE-2024-39347
5.9

This vulnerability allows man-in-the-middle attackers to bypass firewall protections and access sensitive internal network resources on Synology route...

Jun 28, 2024
CVE-2024-23847
5.9

This CVE describes an incorrect default permissions vulnerability in Unifier and Unifier Cast software that allows local attackers to execute arbitrar...

May 31, 2024
CVE-2026-24413
5.5

The Icinga 2 MSI installer on Windows sets overly permissive folder permissions, allowing all local users to read sensitive files including private ke...

Jan 29, 2026
CVE-2025-43519
5.5

A permissions vulnerability in macOS allows applications to bypass intended restrictions and access sensitive user data. This affects users running ma...

Dec 12, 2025
CVE-2025-54866
5.5

This vulnerability exposes the Wazuh agent authentication password file to all authenticated users on Windows systems, allowing local attackers to rea...

Nov 21, 2025
CVE-2025-13193
5.5

This vulnerability in libvirt allows unprivileged users to read snapshots of shut-down virtual machines, exposing guest OS contents. It affects system...

Nov 17, 2025
CVE-2025-55111
5.5

This vulnerability allows local attackers to access sensitive SSL keys, passwords, and policy files due to overly permissive file permissions in Contr...

Sep 16, 2025
CVE-2025-6264
5.5

This vulnerability in Velociraptor allows users with COLLECT_CLIENT permissions (typically Investigator role) to execute the Admin.Client.UpdateClient...

Jun 20, 2025
CVE-2025-21106
5.5

Dell Recover Point for Virtual Machines 6.0.X has weak file system permissions that allow local low-privileged attackers to access non-sensitive resou...

Feb 20, 2025
CVE-2024-51764
5.5

This vulnerability in HPE Data Management Framework (DMF) Suite (CXFS) allows unauthorized local or cluster access depending on configuration. It affe...

Nov 15, 2024
CVE-2024-47240
5.5

Dell Secure Connect Gateway 5.24 has incorrect default file permissions that allow local low-privileged attackers to access the file system. This coul...

Oct 18, 2024
CVE-2024-5474
5.5

A local privilege escalation vulnerability in Lenovo's Dolby Vision Provisioning software allows attackers to read arbitrary files with elevated privi...

Oct 11, 2024
CVE-2024-44151
5.5

This CVE describes a macOS permissions vulnerability where applications can bypass file system protections to modify restricted areas. It affects macO...

Sep 17, 2024
CVE-2024-27888
5.5

This CVE describes a macOS permissions vulnerability that allows applications to modify protected areas of the file system. The issue affects macOS sy...

Jul 29, 2024

About CWE-276 (CWE-276)

Our database tracks 436 CVEs classified as CWE-276, with 59 rated critical and 283 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free