Fallos del tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2026-39874HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoEPSS 0.2%CVE-2024-13948MEDIUMInsecure PermissionsEPSS 0.1%CVE-2023-32492MEDIUM Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exEPSS 0.1%CVE-2026-4793HIGHAn incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files EPSS 0.1%CVE-2020-36652MEDIUMFile and Directory Permissions Vulnerability in Hitachi Automation Director, Hitachi Infrastructure Analytics Advisor, Hitachi Ops CenterEPSS 0.1%CVE-2020-36611MEDIUMFile and Directory Permission Vulnerability in Hitachi Tuning ManagerEPSS 0.1%CVE-2024-35201MEDIUMIncorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalatioEPSS 0.1%CVE-2025-24864HIGHIncorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerabEPSS 0.1%CVE-2026-56301MEDIUMNuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on LinuxEPSS 0.1%CVE-2021-37000HIGHSome Huawei wearables have a permission management vulnerability.EPSS 0.1%CVE-2025-22447HIGHIncorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulneraEPSS 0.1%CVE-2025-0543HIGHG DATA Security Client Local privilege escalationEPSS 0.1%CVE-2023-25542HIGH Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated localEPSS 0.1%CVE-2025-2782MEDIUMWatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation DirectoryEPSS 0.1%CVE-2024-32861HIGHSoftware House C•CURE - CouchDB executable protectionEPSS 0.1%CVE-2025-61035HIGHThe seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik fileEPSS 0.1%CVE-2023-50236HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folderEPSS 0.1%CVE-2022-33963MEDIUMIncorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allowEPSS 0.1%CVE-2025-23297HIGHNVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unpriEPSS 0.1%CVE-2022-36391MEDIUMIncorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially EPSS 0.1%