Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 6/31
7.3
CVE-2024-13948

Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat

7.3
CVE-2025-46355

Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY

7.3
CVE-2025-49144

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerabilit

7.3
CVE-2025-5199

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker

7.3
CVE-2025-8485

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex

7.3
CVE-2025-64724

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with wo

7.1
CVE-2025-24176

A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7

7.1
CVE-2025-32981

NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

7.1
CVE-2025-45467

Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethe

7.1
CVE-2025-10918

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticate

7.0
CVE-2024-49724

In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected

7.0
CVE-2025-53945

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prio

7.0
CVE-2025-10231

An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstanc

7.0
CVE-2025-43887

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerab

6.8
CVE-2025-27521

Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vul

6.8
CVE-2025-20984

Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to

6.7
CVE-2024-55930

Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil

6.7
CVE-2025-24826

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy

6.7
CVE-2024-32942

Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenti

6.7
CVE-2024-42419

Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenti

6.7
CVE-2024-28954

Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentiall

6.7
CVE-2024-47550

Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to pote

6.7
CVE-2025-20095

Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated

6.7
CVE-2025-48959

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect

6.7
CVE-2025-20023

Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to p

6.7
CVE-2025-20087

Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated

6.7
CVE-2025-26470

Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may

6.7
CVE-2025-27559

Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated use

6.7
CVE-2025-27246

Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: Use

6.7
CVE-2025-27711

Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 wit

6.7
CVE-2025-30518

Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may all

6.7
CVE-2025-31940

Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3:

6.6
CVE-2025-8421

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during i

6.5
CVE-2024-54564

This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom

6.5
CVE-2025-41665

An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de

6.5
CVE-2024-55398

4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.

6.5
CVE-2025-43507

A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 an

6.4
CVE-2025-7195

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used

6.4
CVE-2025-57852

A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas

6.4
CVE-2025-58712

A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file

6.4
CVE-2025-57848

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from

6.4
CVE-2025-57850

A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p

6.2
CVE-2024-56440

Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may ca

6.2
CVE-2024-58046

Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may

6.2
CVE-2024-58050

Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may

6.2
CVE-2025-20910

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access da

6.2
CVE-2025-46587

Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may a

6.2
CVE-2025-46185

An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via

6.1
CVE-2025-39201

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to

5.9
CVE-2025-27612

libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the ten

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started