Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2025-13905HIGHCWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or moEPSS 0.1%CVE-2025-53947MEDIUMCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Default PermissionsEPSS 0.1%CVE-2025-27246MEDIUMIncorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may aEPSS 0.1%CVE-2026-2026MEDIUMImproper Access Control Allows Denial of ServiceEPSS 0.1%CVE-2025-61667HIGHDatadog Linux Host Agent affected by local privilege escalation due to insufficient pycache permissionsEPSS 0.1%CVE-2024-58050MEDIUMVulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confiEPSS 0.1%CVE-2025-48512HIGHIncorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attackEPSS 0.1%CVE-2026-0432HIGHIncorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalatiEPSS 0.1%CVE-2025-1789MEDIUMLocal privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gaiEPSS 0.1%CVE-2025-27711MEDIUMIncorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User AppEPSS 0.1%CVE-2025-8421MEDIUMAn improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could aEPSS 0.1%CVE-2026-6718MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2024-43081HIGHIn installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the codEPSS 0.1%CVE-2026-24414MEDIUMIcinga for Windows certificate can have too-open permissionsEPSS 0.1%CVE-2025-43887HIGHDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileEPSS 0.1%CVE-2026-0539HIGHLocal Privilege Escalation in pcvisit service clientEPSS 0.1%CVE-2026-21765HIGHHCL BigFix Platform is affected by insecure permissions on private cryptographic keysEPSS 0.1%CVE-2022-25815MEDIUMPendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized EPSS 0.1%CVE-2026-11813HIGHA potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated usEPSS 0.1%CVE-2022-25814MEDIUMPendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthEPSS 0.1%