Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2020-36652MEDIUMFile and Directory Permissions Vulnerability in Hitachi Automation Director, Hitachi Infrastructure Analytics Advisor, Hitachi Ops CenterEPSS 0.1%CVE-2026-56301MEDIUMNuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on LinuxEPSS 0.1%CVE-2025-24864HIGHIncorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerabEPSS 0.1%CVE-2025-22447HIGHIncorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulneraEPSS 0.1%CVE-2026-4793HIGHAn incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files EPSS 0.1%CVE-2026-48790MEDIUMturso-cli persists Turso platform JWT with world-readable (0o644) file permissionsEPSS 0.1%CVE-2021-37000HIGHSome Huawei wearables have a permission management vulnerability.EPSS 0.1%CVE-2024-35201MEDIUMIncorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalatioEPSS 0.1%CVE-2024-32861HIGHSoftware House C•CURE - CouchDB executable protectionEPSS 0.1%CVE-2025-0543HIGHG DATA Security Client Local privilege escalationEPSS 0.1%CVE-2025-2782MEDIUMWatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation DirectoryEPSS 0.1%CVE-2025-61035HIGHThe seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik fileEPSS 0.1%CVE-2023-25542HIGH Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated localEPSS 0.1%CVE-2023-50236HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folderEPSS 0.1%CVE-2022-40971MEDIUMIncorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to EPSS 0.1%CVE-2023-28079HIGH PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can EPSS 0.1%CVE-2025-23297HIGHNVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unpriEPSS 0.1%CVE-2022-33963MEDIUMIncorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allowEPSS 0.1%CVE-2023-22440MEDIUMIncorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user EPSS 0.1%CVE-2022-30338MEDIUMIncorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable EPSS 0.1%