CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,533 vulnerabilities with CWE-276
CVE-2026-44468
HIGH
Incorrect Default Permissions in CODESYS Development System
CVSS 7.8
CVE-2026-8487
MEDIUM
Incorrect default permissions vulnerability in Progress Software MOVEit Automation
CVSS 6.5
CVE-2026-47107
HIGH
Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration
CVSS 8.1
CVE-2026-0432
HIGH
Amd Ryzen™ 4000 Series Mobile Processors With Radeon™ Graphics - Incorrect Default Permissions
CVE-2026-27680
LOW
CSS Injection vulnerability in SAP NetWeaver Application Server ABAP
CVSS 3.1
CVE-2026-36742
MEDIUM
Hiseeu C90 v5.7.15 - Insecure Permissions
CVSS 6.8
CVE-2026-21015
MEDIUM
Samsung Mobile Devices - Info Disclosure
CVSS 5.5
CVE-2026-20718
MEDIUM
Intel(R) NPU Driver software installers < 32.0.100.4511 - Escalation of Privilege via Incorrect Default Permissions
CVE-2026-41712
HIGH
ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
CVSS 7.5
CVE-2026-45393
HIGH
Cribl Edge < 4.17.1 - Improper Input Validation
CVSS 7.8
CVE-2026-0539
HIGH
Local Privilege Escalation in pcvisit service client
CVE-2026-6823
HIGH
HKUDS OpenHarness Insecure Default Remote Channel Allowlist
CVSS 8.2
CVE-2026-6819
HIGH
HKUDS OpenHarness Plugin Management Command Exposure
CVSS 8.8
CVE-2026-39454
HIGH
SKYSEA Client View <=21.200.07j - Privilege Escalation
CVSS 7.8
CVE-2026-30811
MEDIUM
Missing Authorization in Configuration Ajax Endpoint leads to Information Disclosure
CVSS 6.5
CVE-2026-21013
MEDIUM
Samsung Galaxy Wearable <2.2.68.26 - Info Disclosure
CVSS 5.5
CVE-2026-25203
HIGH
Samsung MagicINFO 9 Server < 21.1091.1 - Local Privilege Escalation via Incorrect Default Permissions
CVSS 7.8
CVE-2026-21765
HIGH
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
CVSS 8.8
CVE-2026-34450
MEDIUM
Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Tool
CVSS 4.4
CVE-2026-32983
MEDIUM
SSL/TLS Renegotiation DoS in Wazuh Manager authd service
CVSS 5.8
CVE-2026-0748
MEDIUM
Access bypass in Drupal 7 i18n_node translation UI
CVSS 4.3
CVE-2026-32680
HIGH
RATOC RAID Monitoring Manager for Windows <2.00.009.260220 - Privilege Escalation
CVSS 7.8
CVE-2026-24063
HIGH
World-writable uninstall script executed as root in Arturia Software Center
CVSS 8.2
CVE-2026-3315
HIGH
ASSA ABLOY Visionline <1.33 - Privilege Escalation
CVSS 7.8
CVE-2026-26131
HIGH
.NET 10.0 < 10.0.4 - Authenticated Privilege Escalation via Incorrect Default Permissions
CVSS 7.8
Details
Vulnerabilities
1,533
Exploit Likelihood
Medium