The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for indivi
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local S
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permis
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read per
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters a
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the correspondin
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was p
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Serv
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux En
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, loca
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directo
A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to
A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read acce
A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the sc
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by defa
The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Rea
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitr
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce
ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does
atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforc
llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registr
SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modific
Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system conf
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions),
The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permis
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xd
An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure defau
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though
An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files bec
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations wh
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions),
Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user
The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unpriv
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a se
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permi
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is pr
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all fi
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started