A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replac
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-cr
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafte
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dok
Cilium is open source software for providing and securing network connectivity and loadbalancing between application wor
Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary c
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing at
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permis
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has acc
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inh
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not ali
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system s
RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origi
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation o
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerabil
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn
Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attac
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated pr
An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service l
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-cra
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installat
Incorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an au
Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to po
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the dire
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user d
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an uns
In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe
In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing p
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless deb
A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an a
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by th
Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a loc
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an i
upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binar
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated us
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacki
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for i
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default inst
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieg
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a loc
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started