Weaknesses of type CWE-276

952 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2022-42446MEDIUMHCL Sametime 12.0 and 12.0FP1 anonymous users have directory lookup accessEPSS 0.4%CVE-2023-21513MEDIUMImproper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to opeEPSS 0.4%CVE-2023-32698HIGHnfpm vulnerable to Incorrect Default PermissionsEPSS 0.4%CVE-2024-48292HIGHAn issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackeEPSS 0.4%CVE-2022-20452HIGHIn initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lEPSS 0.4%CVE-2023-26077—Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.EPSS 0.4%CVE-2022-0486MEDIUMPrivileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 0.4%CVE-2024-47593MEDIUMInformation Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.4%CVE-2021-21912HIGHA privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2EPSS 0.4%CVE-2026-48725HIGHWarp may allow terminal output to access the local clipboard through OSC 52EPSS 0.4%CVE-2023-1693HIGHThe Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentialityEPSS 0.4%CVE-2024-37038HIGHCWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interfaceEPSS 0.4%CVE-2020-7004—VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in eEPSS 0.4%CVE-2022-44561HIGHThe preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized appEPSS 0.4%CVE-2025-35062MEDIUMNewforma Info Exchange (NIX) default anonymous accessEPSS 0.4%CVE-2024-46916HIGHDiebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before theEPSS 0.4%CVE-2024-54564MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3EPSS 0.4%CVE-2021-40396HIGHA privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replacEPSS 0.4%CVE-2021-40388HIGHA privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to EPSS 0.4%CVE-2021-40389HIGHA privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be reEPSS 0.4%