The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traver
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
CMSimple 5.16 allows the user to edit log.php file via print page.
CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats u
MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution p
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named p
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user c
ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged
Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R
An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execut
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerab
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within S
A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has
Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat
Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys
A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallat
there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of priv
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul
A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part o
In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated
In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could le
In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that
In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permiss
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DAT
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vuln
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S
This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installa
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.
Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started