In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of p
Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound grou
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile)
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate pri
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BA
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authentic
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able
Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" f
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate priv
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code vi
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies o
Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as
Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated
langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an o
Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNM
Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission
The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during
An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Di
An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati
In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use p
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local a
There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files
Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric
In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bound
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This c
there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privil
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a lo
In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo
In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocki
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission
By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil
By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file
By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file
By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)
By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f
In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypas
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started