TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available afte
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-Rem
Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insec
Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary co
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after fre
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set p
CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run comm
An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code du
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal syste
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to es
EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privileg
An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writa
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the d
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ
Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability
Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made us
Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.Th
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with loc
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate
IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect f
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured manage
Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resourc
An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged lo
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 1
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applic
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local at
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attack
An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to th
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Serve
In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local esc
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windo
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53
Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate
The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started