CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,533 vulnerabilities with CWE-276
CVE-2026-39875
HIGH
Apple macOS - Incorrect Default Permissions
CVSS 7.8
CVE-2026-39874
HIGH
Apple macOS - Incorrect Default Permissions
CVSS 7.8
CVE-2026-17497
HIGH
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVSS 8.3
CVE-2026-16247
HIGH
Insecure permission overwrite due to execution of LogPathConfig.exe while installing _connect.BRAIN
CVSS 7.3
CVE-2026-16246
HIGH
Insecure permission assignment due to execution of LogPathConfig.exe during setup
CVSS 7.3
CVE-2026-40952
HIGH
Privilge misconfiguration in Secure Access installers
CVSS 7.8
CVE-2026-61828
HIGH
nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`
CVE-2026-53657
HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
CVSS 8.2
CVE-2026-57895
HIGH
Fuji Electric Co.,ltd. Pupsman - Incorrect Default Permissions
CVSS 7.8
CVE-2026-57919
HIGH
Matrix42 Empirum < 25.5 and 26.x < 26.2 - Privilege Escalation via Named Pipe IPC
CVSS 7.8
CVE-2026-57924
MEDIUM
Jetbrains YouTrack < 2026.2.16593 - Incorrect Default Permissions
CVSS 4.3
CVE-2026-48935
LOW
Node - Incorrect Default Permissions
CVSS 3.3
CVE-2026-48725
HIGH
Warp may allow terminal output to access the local clipboard through OSC 52
CVSS 8.1
CVE-2026-56301
MEDIUM
Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux
CVSS 5.5
CVE-2026-12602
HIGH
Incorrect permissions in ArubaSign by Aruba
CVE-2026-12823
LOW
Browserbase Autobrowse Trace Artifact default permission
CVSS 3.3
CVE-2026-53870
MEDIUM
Hermes Agent < 0.16.0 - World-Readable Store Files Expose Secrets
CVSS 5.5
CVE-2026-50255
MEDIUM
Sony Corporation Optical Disc Archive Software For Windows - Incorrect Default Permissions
CVSS 6.7
CVE-2026-11931
MEDIUM
Insecure Permissions on Authentication Token Cache File in Kiro IDE
CVSS 5.5
CVE-2026-49157
HIGH
Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
CVSS 8.8
CVE-2026-48191
LOW
Wrong Permission Handling in Document Search Article Meta Filters
CVSS 3.5
CVE-2026-48190
LOW
Incorrect handling of permissions in External Interface Config Item List module
CVSS 3.5
CVE-2026-33590
HIGH
Insecure default permissions in Portainer CE
CVE-2026-49237
HIGH
Local Privilege Escalation in Canonical Multipass
CVSS 7.8
CVE-2026-44469
HIGH
Incorrect Default Permissions in CODESYS Development System
CVSS 7.8
Details
Vulnerabilities
1,533
Exploit Likelihood
Medium