CWE-377

Insecure Temporary File

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

97 vulnerabilities with CWE-377
CVE-2026-44878 HIGH
Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVSS 7.2
CVE-2026-62294 MEDIUM
Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"
CVE-2026-46406 MEDIUM
Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
CVSS 6.1
CVE-2026-41991 MEDIUM
Predictable Temporary File in GNU gzip
CVSS 4.7
CVE-2026-41001 MEDIUM
Spring Boot - Predictable Temp Directory in Artemis Auto-Configuration
CVSS 5.3
CVE-2026-45384 MEDIUM
bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update
CVSS 6.1
CVE-2026-49135 HIGH
CodexBar < 0.32.0 - Insecure Temporary File Handling in Notarization Workflow
CVSS 7.1
CVE-2026-49134 HIGH
CodexBar < 0.32.0 - Privilege Escalation via CLI Installer Temporary File Race Condition
CVSS 7.1
CVE-2026-40979 MEDIUM
Spring AI 1.0.0-1.0.5 - Info Disclosure
CVSS 6.1
CVE-2026-40973 HIGH
Spring Boot <4.0.6 - Privilege Escalation
CVSS 7.0
CVE-2026-35342 LOW
uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR
CVSS 3.3
CVE-2026-20204 HIGH
Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise
CVSS 7.1
CVE-2026-4822 HIGH
Enter Software Iperius Backup Backup Service Local Privilege Escalation
CVSS 7.0
CVE-2026-25645 MEDIUM
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
CVSS 4.4
CVE-2026-20651 MEDIUM
macOS < 14.8.4, < 15.7.5, < 26.3 - Unprotected User Data Exposure via Temporary File Handling
CVSS 6.2
CVE-2026-25701 HIGH
openSUSE sdbootutil - Insecure Temp File
CVE-2026-20649 HIGH
iPadOS < 26.3 - Unprotected User Data Exposure via Logging Issue
CVSS 7.5
CVE-2026-20618 MEDIUM
macOS Tahoe <26.3 - Info Disclosure
CVSS 5.5
CVE-2025-67223 HIGH
Aranda Service Desk <8.3.12 - Info Disclosure
CVSS 7.5
CVE-2025-14614 MEDIUM
Altera Quartus Prime <24.1 - Insecure Temp File
CVSS 6.7
CVE-2025-14612 MEDIUM
Quartus Prime Pro <25.1.1 - Info Disclosure
CVSS 6.7
CVE-2025-66625 MEDIUM
Umbraco CMS 10.0.0-13.12.0 - Authenticated Arbitrary File Existence Enumeration via Dictionary Upload
CVSS 4.9
CVE-2025-14307 HIGH
Robocode 1.9.3.6 - Insecure Temporary File Creation in AutoExtract Component
CVSS 8.1
CVE-2025-46369 HIGH
Dell Alienware Command Center <6.10.15.0 - Privilege Escalation
CVSS 7.8
CVE-2025-46368 MEDIUM
Dell Alienware Command Center <6.10.15.0 - Info Disclosure
CVSS 6.6
Details
Vulnerabilities 97