Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 3/31
4.3
CVE-2025-15334

Tanium addressed an information disclosure vulnerability in Threat Response.

4.3
CVE-2025-15335

Tanium addressed an information disclosure vulnerability in Threat Response.

4.3
CVE-2026-0748

In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content"

4.3
CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

3.5
CVE-2026-48190

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated c

3.5
CVE-2026-48191

An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Met

3.3
CVE-2026-12823

A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the compon

3.3
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with

3.1
CVE-2026-27680

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj

3.1
CVE-2026-19841

A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of th

3.1
CVE-2026-19893

A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf

CVE-2025-15523

MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis

CVE-2025-13905

CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse s

CVE-2026-0539

Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th

CVE-2026-20718

Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring

CVE-2025-48512

Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c

CVE-2026-0432

Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev

CVE-2025-48516

Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc

CVE-2026-33590

Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access a

CVE-2025-15642

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad

CVE-2026-12602

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig

CVE-2025-27462

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

CVE-2025-27463

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

CVE-2025-27464

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

CVE-2026-61828

Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and

CVE-2026-21074

Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands wi

CVE-2025-48505

Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to

CVE-2025-61970

Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to

CVE-2026-78553

RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil

9.9
CVE-2025-40585

A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain

9.8
CVE-2022-41572

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server be

9.8
CVE-2024-55225

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, inc

9.8
CVE-2024-57684

An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at

9.8
CVE-2025-24093

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma

9.8
CVE-2024-55215

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter

9.8
CVE-2024-57604

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

9.8
CVE-2024-56525

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ

9.8
CVE-2025-27154

Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store

9.8
CVE-2025-27677

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links

9.8
CVE-2025-27682

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Per

9.8
CVE-2024-53351

Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio

9.8
CVE-2025-25535

HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted

9.8
CVE-2025-24172

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS

9.8
CVE-2025-24195

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonom

9.8
CVE-2025-24207

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma

9.8
CVE-2025-24238

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, m

9.8
CVE-2025-30465

A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, ma

9.8
CVE-2025-4660

A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access co

9.8
CVE-2025-6179

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a loca

9.8
CVE-2014-7210

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered tha

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started