CWE-278Variant

Insecure Preserved Inherited Permissions

Incomplete in the CWE catalog · 5 CVEs mapped

5
CVEs mapped
7.2
Median CVSS
What it is

A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.

Recent examples
6.7cvss
CVE-2026-71477

CVE-2026-71477 - MEDIUM Severity Vulnerability

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a root-installed executable, especially when MISE_INSTALL_PATH targets a shared location such as /usr/local/bin. This issue is fixed in version 2026.7.1.

MEDIUMno explanation yet
0%
epss
7.3cvss
CVE-2026-6265

Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2

Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1

HIGHno explanation yet
0%
epss
7.2cvss
CVE-2025-2947

IBM i privilege escalation

IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain root access to the host operating system.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-278
Abstraction
Variant
Structure
Simple
Status
Incomplete