CWE-277Variant

Insecure Inherited Permissions

Draft in the CWE catalog · 50 CVEs mapped

50
CVEs mapped
6.7
Median CVSS
What it is

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

Recent examples
7.3cvss
CVE-2026-9046

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the…

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

HIGHno explanation yet
0%
epss
9.1cvss
CVE-2026-7891

A vulnerability has been identified in Mendix Runtime (All versions)

A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications.

CRITICALno explanation yet
0%
epss
5.5cvss
CVE-2026-20630

CVE-2026-20630 - MEDIUM Severity Vulnerability

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access protected user data.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-277
Abstraction
Variant
Structure
Simple
Status
Draft