VulnSea

CWE-276

CVEs classified under CWE-276, newest first.

47 CVEsRSS

CVE-2026-82163Medium· 5.5
today

Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability

Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disc…

SunlitDell · Command | Intel vPro Out of Bandvia CVEORG
CVE-2026-82165Medium· 5.5
today

Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability

Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Inf…

SunlitDell · Command | Integration Suite for System Centervia CVEORG
CVE-2026-92252Medium· 5.9
yesterday

Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Us…

Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Us…

SunlitWatchDog · Anti-VirusEPSS 0.10%via NVD
CVE-2026-87886High· 7.8CISA KEV0dayPoC
4d ago

Local privilege escalation due to insecure file permissions

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…

Abyssalacronis · acronis_backupEPSS 0.25%via NVD
CVE-2026-86359High· 8.5
5d ago

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

TwilightDell · Repository ManagerEPSS 0.24%via NVD
CVE-2026-48722Medium· 5.5
6d ago

Nextflow is a DSL for data-driven computational pipelines

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.…

Sunlitnextflow-io · nextflowEPSS 0.10%via NVD
CVE-2026-86836High· 8.4
1w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a dir…

TwilightEclipse Foundation · Eclipse AnkaiosEPSS 0.09%via NVD
CVE-2026-11813High· 7.8
1w ago

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

TwilightLenovo · FileZ ClientEPSS 0.10%via NVD
CVE-2026-52766Critical· 9.1PoC
2w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that arra…

AbyssalYesWiki · yeswikiEPSS 0.33%via NVD
CVE-2026-75166High· 8.8
2w ago

Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password

Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated att…

TwilightEPSS 0.49%via NVD
CVE-2026-77393High· 8.8
2w ago

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts)

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to De…

TwilightEPSS 0.51%via NVD
CVE-2026-81302High· 7.8
2w ago

PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.

PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.

TwilightEPSS 0.15%via NVD
CVE-2026-53657High· 8.2
1mo ago

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Twilightlima-vm · github.com/lima-vm/lima/v2EPSS 0.20%via GHSA
CVE-2026-63425High· 7.8
1mo ago

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Twilightlenovo · dock_managerEPSS 0.11%via NVD
CVE-2026-65940Medium· 6.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

SunlitEPSS 0.21%via NVD
CVE-2026-59119High· 7.3
1mo ago

PowerShell Elevation of Privilege Vulnerability

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · PowerShell 7.4EPSS 0.32%via CVEORG
CVE-2026-48790Medium· 5.5
1mo ago

Turso CLI is the command line interface (CLI) to the open-source database Turso

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credenti…

Sunlittursodatabase · github.com/tursodatabase/turso-cliEPSS 0.10%via NVD
CVE-2026-4793High· 7.3
1mo ago

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

Twilightsynology · assistantEPSS 0.15%via NVD
CVE-2026-17497High· 8.3
1mo ago

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore in…

TwilightEPSS 0.46%via NVD
CVE-2024-58356None
2mo ago

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ..

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten…

SunlitEPSS 0.20%via NVD
CVE-2023-54366High· 8.8
2mo ago

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publ…

TwilightEPSS 0.46%via NVD
CVE-2026-57919High· 7.8
2mo ago

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker…

TwilightEPSS 0.18%via NVD
CVE-2026-12823Low· 3.3
3mo ago

A security flaw has been discovered in Browserbase Skills up to 20260526

A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires…

SunlitEPSS 0.16%via NVD
CVE-2026-53856Medium· 5.5
3mo ago

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

Sunlitopenclaw · openclawEPSS 0.09%via GHSA
CVE-2026-53870Medium· 5.5
3mo ago

Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)

Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)

Sunlithermes-agent · hermes-agentEPSS 0.11%via GHSA
GHSA-534h-c3cw-v3h9Medium· 5.5
3mo ago

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Sunlitnuxt · nuxtvia GHSA
CVE-2026-8487Medium· 6.5
4mo ago

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Sunlitprogress · moveit_automationEPSS 0.28%via NVD
CVE-2025-57847Medium· 6.4
5mo ago

A container privilege escalation flaw was found in certain Ansible Automation Platform images

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an …

Sunlitredhat · ansible_automation_platformEPSS 0.16%via NVD
CVE-2025-8766Medium· 6.4
6mo ago

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…

Sunlitredhat · openshift_data_foundationEPSS 0.17%via NVD
CVE-2025-13193Medium· 5.5
10mo ago

A flaw was found in libvirt

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure v…

SunlitEPSS 0.12%via NVD
CWE-276 vulnerabilities (CVEs) · VulnSea