In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions
An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticat
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts fo
ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folde
An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installa
The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change t
An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical f
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection i
An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in manage
A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by
In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, th
In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local atta
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administra
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol
OX App Suite through 7.10.2 has Incorrect Access Control.
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain pas
A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to byp
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to byp
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the setti
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations
Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifact
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a
Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convin
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass n
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convin
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass conten
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof securi
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and oth
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, a
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get admi
The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate wi
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names
A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dyn
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup fil
An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation
In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure wit
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started