The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5,
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS
A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura
A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local att
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, sho
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due t
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting fr
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permission
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.
Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private"
Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker
A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerabi
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the l
Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's aut
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316
A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionali
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.
Incorrect default permissions in the Intel(R) Support android application before version v23.02.07 may allow a privilege
In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resou
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permis
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read perm
Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Re
A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and
PowerProtect Agent for File System Version 19.14 and prior, contains an incorrect default permissions vulnerability in
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to re
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulne
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 co
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial conf
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause per
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Win
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitr
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execut
Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affe
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerabil
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started