CWE-276: CWE-276
Yearly Trend
Top Affected Vendors
All CWE-276 CVEs (436)
This vulnerability involves incorrect default permissions in Intel oneAPI DPC++/C++ Compiler installers, allowing authenticated local users to potenti...
Aug 12, 2025This vulnerability involves incorrect default permissions in some Intel Graphics Driver installers, allowing authenticated local users to potentially ...
Aug 12, 2025This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows due to insecure file permissions. Attac...
Jun 4, 2025This vulnerability in Intel RealSense SDK software allows authenticated local users to escalate privileges due to incorrect default permissions. It af...
May 13, 2025This vulnerability allows authenticated local users to escalate privileges due to incorrect default permissions in Intel Graphics Driver installers. A...
May 13, 2025This vulnerability in Intel DSA installer for Windows allows authenticated local users to escalate privileges due to incorrect default permissions. At...
Feb 12, 2025This CVE describes a local privilege escalation vulnerability in Acronis Snap Deploy for Windows due to insecure folder permissions. Attackers with lo...
Jan 28, 2025Xerox Workplace Suite has insecure default folder permissions that allow unauthorized users to access, modify, or delete files within the application'...
Jan 23, 2025This vulnerability in Intel Distribution for Python allows authenticated local users to escalate privileges due to incorrect default file permissions....
Nov 13, 2024This vulnerability in Intel Binary Configuration Tool for Windows allows authenticated local users to escalate privileges due to incorrect default per...
Nov 13, 2024This vulnerability allows authenticated administrators in Mitel MiCollab's NuPoint Messenger component to escalate privileges and execute arbitrary co...
Oct 21, 2024This vulnerability in Intel Distribution for GDB software allows authenticated local users to escalate privileges due to incorrect default permissions...
Aug 14, 2024This vulnerability allows authenticated users with local access to escalate privileges due to incorrect default permissions in Intel Connectivity Perf...
Aug 14, 2024This vulnerability allows attackers with administrative access to install unauthorized applications on affected Toshiba multifunction printers. It aff...
Jun 14, 2024This vulnerability allows authenticated users with local access to Intel Server Boards to escalate privileges due to incorrect default permissions in ...
May 16, 2024An improper default permission vulnerability in Lenovo Dock Manager allows authenticated local users to redirect log files with elevated privileges du...
Nov 12, 2025Kaminari pagination library for Ruby on Rails has insecure file permissions that could allow unauthorized write access to specific Ruby files. This co...
May 27, 2024CVE-2025-15339 is an incorrect default permissions vulnerability in Tanium Discover that allows unauthorized users to access sensitive information. Th...
Feb 5, 2026CVE-2025-15340 is an incorrect default permissions vulnerability in Tanium Comply that allows unauthorized users to access or modify security complian...
Feb 5, 2026CVE-2025-15341 is an incorrect default permissions vulnerability in Tanium Benchmark that allows unauthorized users to access sensitive configuration ...
Feb 5, 2026CVE-2025-15343 is an incorrect default permissions vulnerability in Tanium Enforce that allows local users to gain elevated privileges. This affects o...
Feb 5, 2026CVE-2025-15336 is an incorrect default permissions vulnerability in Tanium Performance that allows authenticated users to access or modify resources t...
Feb 5, 2026CVE-2025-15337 is an incorrect default permissions vulnerability in Tanium Patch that allows unauthorized users to access or modify patch management d...
Feb 5, 2026CVE-2025-15338 is an incorrect default permissions vulnerability in Tanium Partner Integration that allows unauthorized access to sensitive functional...
Feb 5, 2026This CVE describes a privacy vulnerability in Apple operating systems where applications could fingerprint users by accessing sensitive data. The issu...
Nov 4, 2025An attacker with low-privileged remote access can trigger a watchdog reboot on affected PLC devices due to incorrect default permissions on a configur...
Jul 8, 2025This vulnerability allows files received via AirDrop to bypass macOS/iOS quarantine flagging, which normally warns users about potentially unsafe file...
Mar 21, 2025This vulnerability in Microsoft Edge (Chromium-based) allows an attacker to potentially access sensitive information from the browser's memory or proc...
Sep 12, 2024A container privilege escalation vulnerability in CodeReady Workspaces images allows attackers with container command execution to modify the /etc/pas...
Dec 2, 2025This vulnerability allows attackers with non-root access inside affected containers to modify the /etc/passwd file due to insecure group-writable perm...
Aug 7, 2025This vulnerability allows local attackers to access Galaxy Watch Gallery data due to incorrect default permissions. It affects Samsung Galaxy Watch de...
Mar 6, 2025This vulnerability involves improper access permissions in Huawei's HDC module, allowing unauthorized access to sensitive service data. It affects Hua...
Mar 4, 2025This vulnerability in IBM Security Access Manager Docker allows local users to access sensitive information within the container due to incorrect defa...
Jun 28, 2024This CVE describes an improper permissions vulnerability in Kubernetes clusters with Windows nodes. BUILTIN\Users can read container logs and NT AUTHO...
Jul 18, 2024This vulnerability in libcontainer allows tenant containers to inherit capabilities from the main container, potentially leading to privilege escalati...
Mar 21, 2025This vulnerability allows local users on Unix-like systems to view and modify shared memory containing mod_jk configuration due to incorrect default p...
Sep 23, 2024This vulnerability allows man-in-the-middle attackers to bypass firewall protections and access sensitive internal network resources on Synology route...
Jun 28, 2024This CVE describes an incorrect default permissions vulnerability in Unifier and Unifier Cast software that allows local attackers to execute arbitrar...
May 31, 2024The Icinga 2 MSI installer on Windows sets overly permissive folder permissions, allowing all local users to read sensitive files including private ke...
Jan 29, 2026A permissions vulnerability in macOS allows applications to bypass intended restrictions and access sensitive user data. This affects users running ma...
Dec 12, 2025This vulnerability exposes the Wazuh agent authentication password file to all authenticated users on Windows systems, allowing local attackers to rea...
Nov 21, 2025This vulnerability in libvirt allows unprivileged users to read snapshots of shut-down virtual machines, exposing guest OS contents. It affects system...
Nov 17, 2025This vulnerability allows local attackers to access sensitive SSL keys, passwords, and policy files due to overly permissive file permissions in Contr...
Sep 16, 2025This vulnerability in Velociraptor allows users with COLLECT_CLIENT permissions (typically Investigator role) to execute the Admin.Client.UpdateClient...
Jun 20, 2025Dell Recover Point for Virtual Machines 6.0.X has weak file system permissions that allow local low-privileged attackers to access non-sensitive resou...
Feb 20, 2025This vulnerability in HPE Data Management Framework (DMF) Suite (CXFS) allows unauthorized local or cluster access depending on configuration. It affe...
Nov 15, 2024Dell Secure Connect Gateway 5.24 has incorrect default file permissions that allow local low-privileged attackers to access the file system. This coul...
Oct 18, 2024A local privilege escalation vulnerability in Lenovo's Dolby Vision Provisioning software allows attackers to read arbitrary files with elevated privi...
Oct 11, 2024This CVE describes a macOS permissions vulnerability where applications can bypass file system protections to modify restricted areas. It affects macO...
Sep 17, 2024This CVE describes a macOS permissions vulnerability that allows applications to modify protected areas of the file system. The issue affects macOS sy...
Jul 29, 2024About CWE-276 (CWE-276)
Our database tracks 436 CVEs classified as CWE-276, with 59 rated critical and 283 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.
External reference: View CWE-276 on MITRE CWE →
Monitor CWE-276 Vulnerabilities
Get alerted when new CWE-276 CVEs affect your infrastructure.
Start Monitoring Free