Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat
Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY
Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerabilit
In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with wo
A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7
NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethe
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticate
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prio
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstanc
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerab
Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vul
Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy
Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenti
Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenti
Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentiall
Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to pote
Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect
Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to p
Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated
Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may
Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated use
Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: Use
Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 wit
Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may all
Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3:
An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during i
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de
4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 an
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used
A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas
A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file
A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may ca
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access da
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may a
An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to
libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the ten
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started