A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installatio
There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have pe
There is an unauthorized service in the system service. Since the component does not have permission check, resulting in
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escal
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authen
A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of pri
In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a con
In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" d
In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility ser
In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions du
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the recei
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in
The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affe
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examina
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerabilit
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability w
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than t
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote).
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wr
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignm
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system fil
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability ma
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write a
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system c
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain so
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configurati
Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege att
A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was foun
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mi
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world
Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe compon
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators be
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permission
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 befo
There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affec
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started