nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packag
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Appli
Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An u
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular u
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with el
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly no
Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to
Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version
Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated
Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an au
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10
Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an
Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 bef
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmwar
Incorrect default permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installers before versio
Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated u
Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially
Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authen
Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to p
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that wa
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models cou
Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenti
Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated u
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi T
Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Ad
Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitach
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio an
Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3
Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omn
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permis
Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the u
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to mani
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wi
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could pot
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the
Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to
A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects t
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure w
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started