In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. T
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missin
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions t
In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permission
In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lea
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local au
Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1,
Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2,
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent
Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecros
Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl
An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by a
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file syst
Some Huawei wearables have a permission management vulnerability.
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed
DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group
Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect a
Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals end
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the webs
Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will a
Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly C
Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the de
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the ne
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inhe
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no p
In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vecto
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a
Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. A
Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local
A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised ac
Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain pri
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started