An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass pr
INSTEON Hub 2242-222 lacks Web and API authentication
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a priv
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows un
PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, gr
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the use
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installat
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permi
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary coul
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could all
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticat
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall A
Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an auth
Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to po
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before versi
Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authen
In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Appli
Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versio
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions o
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the p
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor
Python keyring lib before 0.10 created keyring files with world-readable permissions.
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to
LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrate
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Wind
A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege es
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 al
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows
A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permiss
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read perm
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users w
A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypas
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline re
Python keyring has insecure permissions on new databases allowing world-readable files to be created
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which coul
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an a
An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all r
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read pas
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started