Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2026-49237HIGHLocal Privilege Escalation in Canonical MultipassEPSS 0.2%CVE-2025-46355HIGHIncorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on WiEPSS 0.2%CVE-2025-52991LOWThe Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This aEPSS 0.2%CVE-2018-25359HIGHSplinterware System Scheduler Pro 5.12 Privilege EscalationEPSS 0.2%CVE-2024-0833HIGHPrivilege Elevation via Telerik Test StudioEPSS 0.2%CVE-2025-57853MEDIUMWeb-terminal: privilege escalation via excessive /etc/passwd permissionsEPSS 0.2%CVE-2024-45067MEDIUMIncorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticated user to potentialEPSS 0.2%CVE-2024-46466HIGHBy default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by EPSS 0.2%CVE-2023-31359HIGHIncorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting inEPSS 0.2%CVE-2025-27464CRITICALWinPVDrivers: Excessive permissions on user-exposed devicesEPSS 0.2%CVE-2024-46463HIGHBy default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perfEPSS 0.2%CVE-2024-46465HIGHBy default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perfEPSS 0.2%CVE-2024-46467HIGHBy default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them pEPSS 0.2%CVE-2024-46462HIGHBy default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perEPSS 0.2%CVE-2025-27462CRITICALWinPVDrivers: Excessive permissions on user-exposed devicesEPSS 0.2%CVE-2024-4229HIGHIncorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software forEPSS 0.2%CVE-2025-27463CRITICALWinPVDrivers: Excessive permissions on user-exposed devicesEPSS 0.2%CVE-2023-31349HIGHIncorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially rEPSS 0.2%CVE-2020-36695MEDIUMFile and Directory Permission Vulnerability in Hitachi Command SuiteEPSS 0.2%CVE-2023-48678MEDIUMSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, WEPSS 0.2%