CWE-276Base

Incorrect Default Permissions

Draft in the CWE catalog · 577 CVEs mapped

577
CVEs mapped
6.8
Median CVSS
What it is

During installation, installed file permissions are set to allow anyone to modify those files.

Recent examples
8.8cvss
CVE-2026-77393

CVE-2026-77393 - HIGH Severity Vulnerability

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

HIGHno explanation yet
1%
epss
7.8cvss
CVE-2026-81302

CVE-2026-81302 - HIGH Severity Vulnerability

PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.

HIGHno explanation yet
0%
epss
none
CVE-2026-9634

CVE-2026-9634 - UNKNOWN Severity Vulnerability

A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-276
Abstraction
Base
Structure
Simple
Status
Draft
References (2)