Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2024-22085MEDIUMAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.EPSS 0.2%CVE-2024-38459HIGHlangchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; thEPSS 0.2%CVE-2024-9167HIGHUnder specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attackeEPSS 0.2%CVE-2025-67813MEDIUMQuest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communicationEPSS 0.2%CVE-2022-21204HIGHImproper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2025-3528HIGHMirror-registry: local privilege escalation due to incorrect permissions in mirror-registryEPSS 0.2%CVE-2024-21938HIGHIncorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directEPSS 0.2%CVE-2025-24107HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18EPSS 0.2%CVE-2022-45153HIGHsaphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.slsEPSS 0.2%CVE-2025-49082MEDIUMPermissions bypass vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56EPSS 0.2%CVE-2025-32981HIGHNETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.EPSS 0.2%CVE-2025-24267HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VenturEPSS 0.2%CVE-2025-6179CRITICALChromeOS Extension Disablement and Developer Mode Bypass via ExtHang3r and ExtPrint3r ExploitsEPSS 0.2%CVE-2025-7195MEDIUMOperator-sdk: privilege escalation due to incorrect permissions of /etc/passwdEPSS 0.2%CVE-2022-33877MEDIUMAn incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FoEPSS 0.2%CVE-2021-3720MEDIUMAn information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (LEPSS 0.2%CVE-2025-52361HIGHInsecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authentEPSS 0.2%CVE-2023-44157LOWLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) beforEPSS 0.2%CVE-2022-26839HIGHDelta Electronics DIAEnergie Incorrect Default PermissionsEPSS 0.2%CVE-2022-3155HIGHWhen saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the recEPSS 0.2%