Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 2/31
6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l

6.7
CVE-2026-0705

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage

6.7
CVE-2025-22849

Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584

6.7
CVE-2025-31655

Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow

6.7
CVE-2025-32453

Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an

6.7
CVE-2025-36511

Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applica

6.7
CVE-2025-36522

Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:

6.7
CVE-2026-27653

The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission

6.7
CVE-2026-21423

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default

6.7
CVE-2026-50255

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne

6.6
CVE-2026-18273

Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows

6.5
CVE-2025-15336

Tanium addressed an incorrect default permissions vulnerability in Performance.

6.5
CVE-2025-15337

Tanium addressed an incorrect default permissions vulnerability in Patch.

6.5
CVE-2025-15338

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

6.5
CVE-2025-15339

Tanium addressed an incorrect default permissions vulnerability in Discover.

6.5
CVE-2025-15340

Tanium addressed an incorrect default permissions vulnerability in Comply.

6.5
CVE-2025-15341

Tanium addressed an incorrect default permissions vulnerability in Benchmark.

6.5
CVE-2025-15343

Tanium addressed an incorrect default permissions vulnerability in Enforce.

6.5
CVE-2026-30811

Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe

6.5
CVE-2026-8487

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da

6.4
CVE-2025-57849

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being

6.4
CVE-2025-8766

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from

6.4
CVE-2025-57847

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th

6.4
CVE-2025-57851

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f

6.4
CVE-2025-57853

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi

6.4
CVE-2025-57854

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from

6.4
CVE-2025-58713

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f

6.3
CVE-2024-58356

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used

6.2
CVE-2020-37160

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder

6.2
CVE-2016-20029

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files

6.2
CVE-2026-81682

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes

6.1
CVE-2026-2026

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all

5.8
CVE-2026-32983

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i

5.8
CVE-2025-15615

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i

5.5
CVE-2026-24413

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.

5.5
CVE-2026-24414

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of W

5.5
CVE-2026-28267

Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit

5.5
CVE-2026-21013

Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive in

5.5
CVE-2026-21015

Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id

5.5
CVE-2026-11931

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok

5.5
CVE-2026-53870

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod

5.5
CVE-2026-56301

Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit

5.5
CVE-2026-48790

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us

5.3
CVE-2025-67813

Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica

5.3
CVE-2025-55132

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev

5.3
CVE-2025-32749

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit

5.0
CVE-2026-28717

Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro

4.7
CVE-2025-52640

HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi

4.4
CVE-2026-34450

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers

4.3
CVE-2025-15333

Tanium addressed an information disclosure vulnerability in Threat Response.

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started