In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584
Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an
Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applica
Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default
Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne
Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows
Tanium addressed an incorrect default permissions vulnerability in Performance.
Tanium addressed an incorrect default permissions vulnerability in Patch.
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
Tanium addressed an incorrect default permissions vulnerability in Discover.
Tanium addressed an incorrect default permissions vulnerability in Comply.
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
Tanium addressed an incorrect default permissions vulnerability in Enforce.
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe
Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being
A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f
A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi
A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from
A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f
SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of W
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit
Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive in
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id
Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok
Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod
Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers
Tanium addressed an information disclosure vulnerability in Threat Response.
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started