Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2025-7024MEDIUMLocal privilege escalation in Windows Server OS through installed Tetra Connectivity Server (TCS)EPSS 0.1%CVE-2025-2781MEDIUMWatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation DirectoryEPSS 0.1%CVE-2026-27653MEDIUMThe installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow aEPSS 0.1%CVE-2025-11575HIGHMongoDB Atlas SQL ODBC driver installation via MSI may leave ACLs unset on custom installation directoriesEPSS 0.1%CVE-2025-54059MEDIUMmelange creates SBOM files in APKs with world-writable permissionsEPSS 0.1%CVE-2024-28954MEDIUMIncorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation EPSS 0.1%CVE-2025-20095MEDIUMIncorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentiallyEPSS 0.1%CVE-2024-47550MEDIUMIncorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalEPSS 0.1%CVE-2026-82163MEDIUMDell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attEPSS 0.1%CVE-2023-43747MEDIUMIncorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticEPSS 0.1%CVE-2024-22378MEDIUMIncorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allowEPSS 0.1%CVE-2024-23974MEDIUMIncorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially enable escalation of pEPSS 0.1%CVE-2026-82165MEDIUMDell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low pEPSS 0.1%CVE-2025-39201MEDIUMA vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system filEPSS 0.1%CVE-2023-30902—A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionEPSS 0.1%CVE-2026-2915MEDIUMHP System Event Utility – Denial of ServiceEPSS 0.1%CVE-2025-13130HIGHRadarr Service Radarr.Console.exe default permissionEPSS 0.1%CVE-2022-20475HIGHIn test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused depEPSS 0.1%CVE-2024-23495MEDIUMIncorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to poteEPSS 0.1%CVE-2023-29244MEDIUMIncorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software insEPSS 0.1%