In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional pass
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymou
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when pub
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_im
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local a
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions
Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ab
Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The ro
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces h
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with
The setup program for the affected product configures its files and folders with full access, which may allow unauthoriz
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local use
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitat
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in r
WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file
WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the f
Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metada
There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerabili
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unautho
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attacke
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to p
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a
In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l
In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local maliciou
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (
PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to
Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authentic
Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated us
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable a
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resou
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker se
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a p
Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers t
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to a
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started