CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,510 vulnerabilities with CWE-276
CVE-2025-20087 MEDIUM
Intel(R) oneAPI DPC++/C++ Compiler - Privilege Escalation
CVSS 6.7
CVE-2025-20023 MEDIUM
Intel(R) Graphics Driver - Privilege Escalation
CVSS 6.7
CVE-2025-8672 HIGH
GIMP < 3.1.4.2 - Unauthenticated TCC Permission Bypass via Bundled Python Interpreter
CVSS 7.8
CVE-2025-7195 MEDIUM
Operator-SDK < 0.15.2 - Incorrect Default Permissions via user_setup Script
CVSS 6.4
CVE-2025-44643 HIGH
Draytek AP903 <1.4.18-AP918R <1.4.9 - Privilege Escalation
CVSS 8.6
CVE-2025-41658 MEDIUM
CODESYS Runtime Toolkit - Info Disclosure
CVSS 5.5
CVE-2025-52361 HIGH
AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 - Command ...
CVSS 7.8
CVE-2025-54085 LOW
Absolute Secure Access < 13.56 - Authenticated Permission Bypass in Management Console
CVSS 3.8
CVE-2025-49084 CRITICAL
Absolute Secure Access < 13.56 - Authenticated Policy Rule Overwrite
CVSS 9.1
CVE-2025-49082 LOW
Absolute Secure Access < 13.56 - Authenticated Permission Bypass in Management Console
CVSS 2.7
CVE-2025-54530 HIGH
JetBrains TeamCity < 2025.07 - Privilege Escalation via Incorrect Directory Permissions
CVSS 7.5
CVE-2025-45467 HIGH
Unitree Go1 <= Go1_2022_05_11 - Insecure Firmware Update Permissions via MD5 Checksum
CVSS 7.1
CVE-2025-8069 HIGH
AWS Client VPN 4.1.0-4.1.0 and 5.0.0-5.2.1 - Unauthenticated Privilege Escalation via OpenSSL Configuration File
CVSS 7.8
CVE-2025-8031 CRITICAL
Firefox and Thunderbird - HTTP Basic Authentication Credential Leak via CSP Report URL Handling
CVSS 9.8
CVE-2025-54059 MEDIUM
melange 0.23.0-0.29.4 - Incorrect Default Permissions in SBOM Files
CVSS 4.4
CVE-2025-53945 HIGH
apko <0.29.5 - Privilege Escalation
CVSS 7.0
CVE-2025-0886 HIGH
Elliptic Labs Virtual Lock Sensor - Privilege Escalation
CVSS 7.8
CVE-2025-7672 MEDIUM
JiranSoft CrossEditor4 <4.6.0.23 - XSS
CVSS 4.3
CVE-2025-5199 HIGH
Canonical Multipass <= 1.15.1 - Privilege Escalation via Launch Daemon File Modification
CVSS 7.3
CVE-2025-41665 MEDIUM
PHOENIX CONTACT AXC F 1152/2152/3152, BPC 9102S, RFC 4072S < 2025.0.2 - DoS via Watchdog Reboot
CVSS 6.5
CVE-2025-46014 HIGH
Honor PC Manager < 16.0.0.118 - Privilege Escalation via iMateBookAssistant Named Pipe
CVSS 8.8
CVE-2025-52991 LOW
Nix/Lix/Guix <2.24.15/2.26.4/2.28.4/2.29.1 - Info Disclosure
CVSS 3.2
CVE-2025-52900 MEDIUM
filebrowser < 2.33.7 - Incorrect Default Permissions
CVSS 5.5
CVE-2025-39201 MEDIUM
MicroSCADA X SYS600 10.0-10.7 - Unauthenticated Denial of Service via Notify Service File Tampering
CVSS 6.1
CVE-2025-49144 HIGH
Notepad++ <8.8.1 - Privilege Escalation
CVSS 7.3
Details
Vulnerabilities 1,510
Exploit Likelihood Medium