Tanium addressed an information disclosure vulnerability in Threat Response.
Tanium addressed an information disclosure vulnerability in Threat Response.
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content"
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated c
An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Met
A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the compon
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of th
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf
MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse s
Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th
Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring
Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev
Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc
Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access a
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands wi
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil
A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server be
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, inc
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Per
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio
HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonom
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, m
A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, ma
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access co
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a loca
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered tha
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started