Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Loc
A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vuln
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 t
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, ma
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to befo
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonom
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenti
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS
KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the vir
XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with
Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execut
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could le
snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability
The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone t
Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via t
Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak
melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) cont
The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS
In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1,
CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer tha
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulne
Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's conf
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to vers
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS
Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili
The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writa
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A loc
An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth
CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An atta
The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in
The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissi
On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it
Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints al
Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6,
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started