conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.2
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a
The Phoenix Code's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-
The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-envir
The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivil
The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivilege
The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileg
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privileg
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows R
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth
CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target inst
The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog L
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify
The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker ca
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in in
Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfi
Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve th
AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could le
OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, all
WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows
WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke
COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows at
An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vu
An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retr
Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capa
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalat
Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-V
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obt
Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.3
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Tas
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due t
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authen
Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (V
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions
An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated
An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows a
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the off
The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerabili
An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation di
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started