An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the Mem
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modi
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys l
HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enab
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE
Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege use
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a
HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote cha
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp a
MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service ex
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability.
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vul
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical R
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installat
Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects M
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file a
A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t
The affected product creates a directory with insecure default permissions during administrative installation. This allo
The affected product extracts installation files to a temporary directory with incorrect default permissions during admi
An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-519
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA
Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Man
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privil
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is e
Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta
Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privileg
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wr
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere
HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 130 CVE records associated with CWE-276 in our database. Of these, 2 are critical severity, 47 are high severity, and 55 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started