Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2024-0034HIGHIn BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This couldEPSS 0.1%CVE-2025-12792LOWThe Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor withEPSS 0.1%CVE-2026-0705MEDIUMLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before bEPSS 0.1%CVE-2025-20087MEDIUMIncorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentiallyEPSS 0.1%CVE-2025-20023MEDIUMIncorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable esEPSS 0.1%CVE-2025-27559MEDIUMIncorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enaEPSS 0.1%CVE-2025-26470MEDIUMIncorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticatEPSS 0.1%CVE-2026-23703HIGHThe installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrativEPSS 0.1%CVE-2024-40660HIGHIn setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the codEPSS 0.1%CVE-2025-32453MEDIUMIncorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilEPSS 0.1%CVE-2025-36511MEDIUMIncorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an eEPSS 0.1%CVE-2022-20448MEDIUMIn buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. TEPSS 0.1%CVE-2025-57851MEDIUMMce: privilege escalation via excessive /etc/passwd permissionsEPSS 0.1%CVE-2025-53919HIGHAn issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, EPSS 0.1%CVE-2025-69604HIGHAn issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary pEPSS 0.1%CVE-2024-43085HIGHIn handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due toEPSS 0.1%CVE-2026-86836HIGHIn Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictaEPSS 0.1%CVE-2021-47761HIGHMilleGPG5 5.7.2 Luglio 2021 (x64) - Local Privilege EscalationEPSS 0.1%CVE-2025-27246MEDIUMIncorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may aEPSS 0.1%CVE-2025-59485MEDIUMIncorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerability is exploited, an EPSS 0.1%