PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this
Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id paramet
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause dis
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not prop
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in
A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configu
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen by
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially en
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbit
Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception
Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privilege
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user
The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of thi
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 bef
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Relea
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release al
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some
Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions.
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting f
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission se
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers
Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-w
Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing wo
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moder
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to
An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permi
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote una
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing a
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate pe
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started