Vulnerabilities (CVE)

Filtered by CWE-276
Angry Yack Logo
Total 1461 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28727 2026-03-06 N/A 7.8 HIGH
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124.
CVE-2026-28717 2026-03-06 N/A 5.0 MEDIUM
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
CVE-2026-26034 2026-03-05 N/A 7.8 HIGH
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.
CVE-2026-21423 1 Dell 1 Powerscale Onefs 2026-03-04 N/A 6.7 MEDIUM
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to code execution, denial of service, elevation of privileges, and information disclosure.
CVE-2026-2915 2026-03-03 N/A N/A
HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.
CVE-2023-31068 1 Tsplus 1 Tsplus Remote Work 2026-03-03 N/A 9.8 CRITICAL
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
CVE-2026-23703 2026-02-27 N/A 7.8 HIGH
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.
CVE-2026-27653 2026-02-27 N/A 6.7 MEDIUM
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
CVE-2025-1789 1 Genetec 1 Genetec Update Service 2026-02-26 N/A 7.8 HIGH
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
CVE-2020-29582 2 Jetbrains, Oracle 4 Kotlin, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Policy and 1 more 2026-02-25 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
CVE-2026-2026 2 Microsoft, Tenable 2 Windows, Nessus Agent 2026-02-24 N/A 6.1 MEDIUM
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.
CVE-2020-1571 1 Microsoft 1 Windows 10 2026-02-23 7.2 HIGH 7.3 HIGH
An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by ensuring Windows Setup properly handles permissions.
CVE-2023-32492 1 Dell 1 Powerscale Onefs 2026-02-20 N/A 5.3 MEDIUM
Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.
CVE-2024-22430 1 Dell 1 Powerscale Onefs 2026-02-20 N/A 5.5 MEDIUM
Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service.
CVE-2025-64724 2 Apple, Arduino 2 Macos, Arduino Ide 2026-02-19 N/A 7.3 HIGH
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious code executes with that user's privileges, enabling privilege escalation and unauthorized access to sensitive data. The fix is included starting from the `2.3.7` release.
CVE-2025-64723 2 Apple, Arduino 2 Macos, Arduino Ide 2026-02-19 N/A 4.4 MEDIUM
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the application process, gaining access to all TCC (Transparency, Consent, and Control) permissions granted to the application. The fix is included starting from the `2.3.7 ` release.
CVE-2026-24413 2 Icinga, Microsoft 2 Icinga, Windows 2026-02-19 N/A 5.5 MEDIUM
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work a ...

Show More

CVE-2025-59030 1 Powerdns 1 Recursor 2026-02-19 N/A 7.5 HIGH
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
CVE-2023-29131 1 Siemens 1 Simatic Cn 4100 Firmware 2026-02-18 N/A 7.4 HIGH
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.
CVE-2026-24780 1 Agpt 1 Autogpt Platform 2026-02-17 N/A 8.8 HIGH
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID without checking the `disabled` flag. Any authenticated user can execute the disabled `BlockInstallationBlock`, which writes arbitrary Python code to the server filesystem and executes it via `__import_ ...

Show More

CVE-2025-69604 1 Shirt-pocket 1 Superduper\! 2026-02-13 N/A 7.8 HIGH
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
CVE-2025-7195 2026-02-11 N/A 5.2 MEDIUM
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd ...

Show More

CVE-2025-32453 2026-02-10 N/A 6.7 MEDIUM
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality ( ...

Show More

CVE-2025-22849 2026-02-10 N/A 6.7 MEDIUM
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and r ...

Show More

CVE-2025-36522 2026-02-10 N/A 6.7 MEDIUM
Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may im ...

Show More

CVE-2025-31655 2026-02-10 N/A 6.7 MEDIUM
Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentialit ...

Show More

CVE-2025-36511 2026-02-10 N/A 6.7 MEDIUM
Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the conf ...

Show More

CVE-2025-15339 1 Tanium 1 Discover 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Discover.
CVE-2025-15341 1 Tanium 1 Benchmark 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
CVE-2025-15343 1 Tanium 1 Enforce 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Enforce.
CVE-2025-15335 1 Tanium 1 Threat Response 2026-02-10 N/A 4.3 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15334 1 Tanium 1 Threat Response 2026-02-10 N/A 4.3 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15333 1 Tanium 1 Threat Response 2026-02-10 N/A 4.3 MEDIUM
Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2025-15340 1 Tanium 1 Comply 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Comply.
CVE-2025-15338 1 Tanium 1 Partner Integration 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
CVE-2025-15337 1 Tanium 1 Patch 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Patch.
CVE-2025-15336 1 Tanium 1 Performance 2026-02-10 N/A 6.5 MEDIUM
Tanium addressed an incorrect default permissions vulnerability in Performance.
CVE-2026-25931 2026-02-10 N/A 7.8 HIGH
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each time settings are fetched. The code coerces any truthy value to true and forwards it to ConfigLoader.setIsTrusted , which in turn allows JavaScript/TypeScript configuration files ( .c ...

Show More

CVE-2020-37160 2026-02-09 N/A 6.2 MEDIUM
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.
CVE-2020-37129 2026-02-05 N/A 9.8 CRITICAL
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.