Falhas do tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, registro, objeto) é criado com permissões padrão que são muito permissivas, permitindo acesso não autorizado. O código não define explicitamente permissões restritivas, deixando o sistema usar padrões inseguros que muitas vezes permitem leitura ou escrita por usuários não previstos.

Exemplo

Um aplicativo cria um arquivo de configuração com credenciais em /tmp/config.ini sem definir permissões — o sistema deixa o arquivo legível por qualquer usuário local (644), expondo senhas. Ou um diretório de upload recebe 777 como padrão, permitindo que qualquer pessoa execute scripts maliciosos nele.

Como mitigar

Sempre defina permissões explícitas e restritivas no momento da criação (umask 0077 para sensíveis, validar permissões em código). Para arquivos com secrets, use 0600 (apenas proprietário); para diretórios de aplicação, 0755 no máximo. Valide periodicamente permissões em produção e documente o modelo de acesso esperado.

CVE-2024-46467HIGHBy default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them pEPSS 0.2%CVE-2024-0833HIGHPrivilege Elevation via Telerik Test StudioEPSS 0.2%CVE-2024-46466HIGHBy default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by EPSS 0.2%CVE-2024-46465HIGHBy default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perfEPSS 0.2%CVE-2025-57853MEDIUMWeb-terminal: privilege escalation via excessive /etc/passwd permissionsEPSS 0.2%CVE-2024-45067MEDIUMIncorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticated user to potentialEPSS 0.2%CVE-2025-27462CRITICALWinPVDrivers: Excessive permissions on user-exposed devicesEPSS 0.2%CVE-2025-27464CRITICALWinPVDrivers: Excessive permissions on user-exposed devicesEPSS 0.2%CVE-2025-27463CRITICALWinPVDrivers: Excessive permissions on user-exposed devicesEPSS 0.2%CVE-2023-31359HIGHIncorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting inEPSS 0.2%CVE-2024-46463HIGHBy default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perfEPSS 0.2%CVE-2023-33240HIGHFoxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previousEPSS 0.2%CVE-2023-32221HIGHEaseUS Todo Backup may allow local privilege escalationEPSS 0.2%CVE-2025-57852MEDIUMOpenshift-ai: privilege escalation via excessive /etc/passwd permissionsEPSS 0.2%CVE-2023-31349HIGHIncorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially rEPSS 0.2%CVE-2023-48678MEDIUMSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, WEPSS 0.2%CVE-2020-36695MEDIUMFile and Directory Permission Vulnerability in Hitachi Command SuiteEPSS 0.2%CVE-2026-18273MEDIUMKenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-16246HIGHInsecure permission assignment due to execution of LogPathConfig.exe during setupEPSS 0.2%CVE-2024-42053HIGHThe MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A locEPSS 0.2%