Threats Tagged 'cwe-276'
View all threats tagged with 'cwe-276'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-276'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-2782: CWE-276 in WatchGuard SSO Terminal Services AgentCVE-2025-2782 0 CVE-2025-2782 is a medium severity vulnerability in WatchGuard SSO Terminal Services Agent version 12.0. It involves improper directory permission configuration when the agent is installed in a non-default directory, potentially allowing an authenticated local attacker to escalate privileges to SYSTEM on the affected Windows system. Join the discussion | CVE Database V5 | 03/28/2025, 22:24:47 UTC Added: 08/08/2026, 02:56:50 UTC |
CVE-2025-2781: CWE-276 in WatchGuard Mobile VPN with SSL ClientCVE-2025-2781 0 CVE-2025-2781 is a vulnerability in WatchGuard Mobile VPN with SSL Client for Windows where improper directory permissions are set when installed in a non-default directory. This misconfiguration can allow an authenticated local attacker to escalate privileges to SYSTEM on the affected system. The vulnerability is rated medium severity with a CVSS score of 6.3. Join the discussion | CVE Database V5 | 03/28/2025, 22:23:50 UTC Added: 08/08/2026, 02:56:50 UTC |
CVE-2025-57848: Incorrect Default Permissions in Red Hat RHEL-8-CNV-4.12CVE-2025-57848 0 Red Hat has released OpenShift Virtualization 4.14.16 images as a product enhancement advisory. This update includes bug fixes and enhancements but does not list any specific fixes for CVE-2025-57848 or other vulnerabilities. The advisory does not provide details on the nature of CVE-2025-57848 beyond its association with CWE-276 (Incorrect Default Permissions). No active exploits are known in the wild. No affected versions are explicitly stated in the advisory. Join the discussion | GCVE Database | 10/23/2025, 20:10:31 UTC Added: 08/06/2026, 18:16:56 UTC |
CVE-2026-17497: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in codexu NoteGenCVE-2026-17497 0 NoteGen versions prior to 0.32.0 include a vulnerability where the Tauri shell plugin grants shell:allow-execute capability for bash, python, and python3 with arbitrary arguments by default. This allows JavaScript running in the application's webview to execute operating system commands with the privileges of the NoteGen process. If an attacker can execute scripts in the webview (e.g., via cross-site scripting), they can achieve full remote code execution on the user's machine. Join the discussion | CVE Database V5 | 07/26/2026, 14:38:08 UTC Added: 07/26/2026, 14:52:37 UTC |
CVE-2026-16247: CWE-276 Incorrect default permissions in Bizerba SE & Co. KG _connect.BRAINCVE-2026-16247 0 In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. Starting with _connect.BRAIN 5.06, the setup no longer executes this tool. Join the discussion | CVE Database V5 | 07/20/2026, 11:54:37 UTC Added: 07/20/2026, 12:27:40 UTC |
CVE-2026-16246: CWE-276 Incorrect default permissions in Bizerba SE & Co. KG BRAIN2CVE-2026-16246 0 In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. Starting with BRAIN2 3.09, the setup no longer executes this tool. However, the optional component Bizerba ScriptService still executes it. Bizerba ScriptService is being deprecated and will no longer be included starting with BRAIN2 version 3.11. Join the discussion | CVE Database V5 | 07/20/2026, 11:51:40 UTC Added: 07/20/2026, 12:27:40 UTC |
CVE-2026-61828: CWE-276: Incorrect Default Permissions in NixOS nixpkgsCVE-2026-61828 0 Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in as the root user without a password when the service is used with mysql or percona-server. This issue is fixed in the 25.11 and 26.05. Join the discussion | CVE Database V5 | 07/15/2026, 14:52:35 UTC Added: 07/15/2026, 15:33:19 UTC |
CVE-2026-53657: CWE-276: Incorrect Default Permissions in lima-vm limaCVE-2026-53657 0 Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because the guest agent socket provides tunneling for arbitrary addresses, including Unix socket addresses for privileged daemons like D-Bus. This issue is fixed in version 2.1.3. Join the discussion | CVE Database V5 | 07/10/2026, 15:42:39 UTC Added: 07/10/2026, 16:33:24 UTC |
CVE-2026-21051: CWE-276: Incorrect Default Permissions in Samsung Mobile Samsung Mobile DevicesCVE-2026-21051 0 Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings. Join the discussion | CVE Database V5 | 07/10/2026, 04:58:13 UTC Added: 07/10/2026, 05:18:15 UTC |
CVE-2025-27464: CWE-276 Incorrect default permissions in Xen Windows PV driversCVE-2025-27464 0 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464 Join the discussion | CVE Database V5 | 07/09/2026, 14:35:38 UTC Added: 07/09/2026, 15:33:27 UTC |
Showing 1 to 10 of 12 results