CWE-279Variant

Incorrect Execution-Assigned Permissions

Draft in the CWE catalog · 23 CVEs mapped

23
CVEs mapped
6.8
Median CVSS
What it is

While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.

Recent examples
4.4cvss
CVE-2026-46388

osquery: Unprivileged users can temporarily read file carve contents

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.

MEDIUMno explanation yet
0%
epss
5.5cvss
CVE-2026-4948

CVE-2026-4948 - MEDIUM Severity Vulnerability

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.

MEDIUMno explanation yet
0%
epss
6.5cvss
CVE-2025-12801

CVE-2025-12801 - MEDIUM Severity Vulnerability

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-279
Abstraction
Variant
Structure
Simple
Status
Draft