An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD
Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an a
Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escal
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for N
In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an u
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute ch
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to byp
Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to con
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V
A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writea
A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default tar
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4,
An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD
A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashbo
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following regist
A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream R
An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwr
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can b
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, su
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited pr
The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can b
Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may all
Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2
Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an a
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permis
An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and
A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads t
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local a
An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.e
Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bi
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged us
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack bef
Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before v
Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may all
Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.4
Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may
Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow
When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured.
Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This fil
Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started