Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2023-21126—In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe IEPSS 0.1%CVE-2023-40132HIGHIn setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missinEPSS 0.1%CVE-2025-31655MEDIUMIncorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of priEPSS 0.1%CVE-2025-36522MEDIUMIncorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications mEPSS 0.1%CVE-2023-21121—In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to impropEPSS 0.1%CVE-2023-21139—In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to locEPSS 0.1%CVE-2023-21138—In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could leEPSS 0.1%CVE-2018-9369HIGHIn bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilEPSS 0.1%CVE-2023-21104MEDIUMIn applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional exEPSS 0.1%CVE-2026-20718MEDIUMIncorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User ApplicationsEPSS 0.1%CVE-2024-43769HIGHIn isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due EPSS 0.1%CVE-2018-9431HIGHIn OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalatioEPSS 0.1%CVE-2024-40655HIGHIn bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the bacEPSS 0.1%CVE-2024-40654HIGHIn multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege withEPSS 0.1%CVE-2024-47012HIGHIn mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could EPSS 0.1%CVE-2024-34730HIGHIn multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This coulEPSS 0.1%CVE-2024-49737HIGHIn applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID duEPSS 0.1%CVE-2026-24413MEDIUMIcinga has insecure permission of %ProgramData%\icinga2\var on WindowsEPSS 0.1%CVE-2018-9432HIGHIn createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This couldEPSS 0.1%CVE-2024-53840HIGHthere is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execuEPSS 0.1%