CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2026-23556 CRITICAL
oxenstored keeps quota related use counts across domain destruction
CVE-2026-58494 MEDIUM
Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
CVSS 6.5
CVE-2026-4360 MEDIUM
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
CVE-2026-44947 MEDIUM
Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
CVE-2026-40767 HIGH
WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-44832 HIGH
Snipe-IT: Privilege Escalation via API Permissions Assignment
CVSS 8.8
CVE-2026-24194 HIGH
Nvidia GeForce - Improper Preservation of Permissions
CVSS 7.8
CVE-2026-39832 CRITICAL
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVSS 9.1
CVE-2026-39828 MEDIUM
Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVSS 6.3
CVE-2026-34744 MEDIUM
MantisBT authorization bypass allows continued access to self-uploaded attachments on private issues
CVE-2026-34600 MEDIUM
Joplin Server delta API returns note content after share access is revoked
CVSS 5.7
CVE-2026-25850 MEDIUM
OpenHarmony <=6.0 filemanagement_storage_service - Permission Preservation Information Leak
CVSS 5.5
CVE-2026-35361 LOW
uutils coreutils mknod Security Label Inconsistency and Broken Cleanup on SELinux Systems
CVSS 3.4
CVE-2026-35351 MEDIUM
uutils coreutils mv Silent Ownership Loss in Cross-Device Operations
CVSS 4.2
CVE-2026-35350 MEDIUM
uutils coreutils cp Unexpected Privileged Executable Creation with -p
CVSS 6.6
CVE-2026-35385 HIGH
OpenSSH <10.3 - Privilege Escalation
CVSS 7.5
CVE-2026-24834 CRITICAL
Kata Containers <3.27.0 - Privilege Escalation
CVSS 9.3
CVE-2025-8325 MEDIUM
Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations
CVSS 6.3
CVE-2025-69875 HIGH
Quick Heal Total Security 23.0.0 - Privilege Escalation via Quarantine Restore Path Manipulation
CVSS 7.8
CVE-2025-9615 LOW
Red Hat Enterprise Linux 6-10 and OpenShift Container Platform 4 - Unauthorized File Access via NetworkManager
CVSS 3.3
CVE-2025-55130 CRITICAL
Node.js 20.0.0-20.19.1 - Authentication Bypass via Symlink Path Traversal
CVSS 9.1
CVE-2025-37735 HIGH
Elastic Defend - Privilege Escalation
CVSS 7.0
CVE-2025-34298 HIGH
Nagios Log Server < 2024R1.3.2 - Privilege Escalation via Email Change Workflow
CVSS 8.8
CVE-2025-26420 MEDIUM
GrantPermissionsActivity - Privilege Escalation
CVSS 4.4
CVE-2025-7346 HIGH
pyload-ng - Unauthenticated Arbitrary Package Creation via Localhost Restriction Bypass
Details
Vulnerabilities 337