CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,533 vulnerabilities with CWE-276
CVE-2026-39875 HIGH
Apple macOS - Incorrect Default Permissions
CVSS 7.8
CVE-2026-39874 HIGH
Apple macOS - Incorrect Default Permissions
CVSS 7.8
CVE-2026-17497 HIGH
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVSS 8.3
CVE-2026-16247 HIGH
Insecure permission overwrite due to execution of LogPathConfig.exe while installing _connect.BRAIN
CVSS 7.3
CVE-2026-16246 HIGH
Insecure permission assignment due to execution of LogPathConfig.exe during setup
CVSS 7.3
CVE-2026-40952 HIGH
Privilge misconfiguration in Secure Access installers
CVSS 7.8
CVE-2026-61828 HIGH
nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`
CVE-2026-53657 HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
CVSS 8.2
CVE-2026-57895 HIGH
Fuji Electric Co.,ltd. Pupsman - Incorrect Default Permissions
CVSS 7.8
CVE-2026-57919 HIGH
Matrix42 Empirum < 25.5 and 26.x < 26.2 - Privilege Escalation via Named Pipe IPC
CVSS 7.8
CVE-2026-57924 MEDIUM
Jetbrains YouTrack < 2026.2.16593 - Incorrect Default Permissions
CVSS 4.3
CVE-2026-48935 LOW
Node - Incorrect Default Permissions
CVSS 3.3
CVE-2026-48725 HIGH
Warp may allow terminal output to access the local clipboard through OSC 52
CVSS 8.1
CVE-2026-56301 MEDIUM
Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux
CVSS 5.5
CVE-2026-12602 HIGH
Incorrect permissions in ArubaSign by Aruba
CVE-2026-12823 LOW
Browserbase Autobrowse Trace Artifact default permission
CVSS 3.3
CVE-2026-53870 MEDIUM
Hermes Agent < 0.16.0 - World-Readable Store Files Expose Secrets
CVSS 5.5
CVE-2026-50255 MEDIUM
Sony Corporation Optical Disc Archive Software For Windows - Incorrect Default Permissions
CVSS 6.7
CVE-2026-11931 MEDIUM
Insecure Permissions on Authentication Token Cache File in Kiro IDE
CVSS 5.5
CVE-2026-49157 HIGH
Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
CVSS 8.8
CVE-2026-48191 LOW
Wrong Permission Handling in Document Search Article Meta Filters
CVSS 3.5
CVE-2026-48190 LOW
Incorrect handling of permissions in External Interface Config Item List module
CVSS 3.5
CVE-2026-33590 HIGH
Insecure default permissions in Portainer CE
CVE-2026-49237 HIGH
Local Privilege Escalation in Canonical Multipass
CVSS 7.8
CVE-2026-44469 HIGH
Incorrect Default Permissions in CODESYS Development System
CVSS 7.8
Details
Vulnerabilities 1,533
Exploit Likelihood Medium