Weaknesses of type CWE-281

225 results

Preservação inadequada de permissões

Ocorre quando uma aplicação cria, copia ou modifica arquivos, processos ou recursos sem manter ou validar as permissões de acesso originais. Isso permite que usuários não autorizados acessem dados sensíveis ou executem operações privilégiadas que deveriam estar restritas.

Example

Um backup de banco de dados é criado com permissões world-readable porque o código copia o arquivo sem preservar o mode 0600 do original, expondo credenciais de produção a qualquer usuário do servidor. Ou um processo filho herda mais privilégios que deveria porque o pai não descarta capabilities do Linux antes de exec().

How to mitigate

Sempre defina explicitamente permissões restritivas ao criar ou copiar recursos sensíveis (chmod 0600 para arquivos, setfacl para ACLs). Valide permissões antes de acessar e remova privilégios desnecessários antes de executar código não confiável (chown, chgrp, umask consciente).

CVE-2025-43701HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impaEPSS 0.4%CVE-2025-43697HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmnEPSS 0.4%CVE-2024-23464HIGHZscaler bypass with administrative privileges on WindowsEPSS 0.4%CVE-2025-43700HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.  This impacts OmEPSS 0.4%CVE-2025-25711HIGHAn issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/adEPSS 0.4%CVE-2022-41963LOWBigBlueButton contains Improper Preservation of Permissions for whiteboardEPSS 0.4%CVE-2024-9333MEDIUMPermission bypass in M-Files Connector for CopilotEPSS 0.4%CVE-2024-44211HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-EPSS 0.4%CVE-2023-45807MEDIUMOpenSearch Issue with tenant read-only permissionsEPSS 0.4%CVE-2024-44193HIGHA logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to eEPSS 0.4%CVE-2024-33921MEDIUMWordPress ReviewX plugin <= 1.6.21 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-50921MEDIUMInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeaEPSS 0.4%CVE-2024-50924MEDIUMInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the EPSS 0.4%CVE-2024-38361LOWPermissions processing error in spacedbEPSS 0.4%CVE-2024-37575HIGHThe Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phEPSS 0.4%CVE-2024-57698HIGHAn issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, EPSS 0.4%CVE-2026-44947MEDIUMStale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in RancherEPSS 0.4%CVE-2025-32697NONECascading protection is not preventing file reversionsEPSS 0.4%CVE-2023-4996MEDIUMLocal privilege escalation EPSS 0.4%CVE-2022-0330A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code onEPSS 0.4%