When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5,
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe perm
An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via t
Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files a
When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu
Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when inst
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute com
An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to ele
An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c
An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe
During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\window
Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo
MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permission
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate pri
Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default P
NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attac
Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This
NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e
Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a
A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra
A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document r
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to ex
An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user
The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates
A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerabili
The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation dir
Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege e
Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19
Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker
A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalatio
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote
Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started