CWE-379Base

Creation of Temporary File in Directory with Insecure Permissions

Incomplete in the CWE catalog · 62 CVEs mapped

62
CVEs mapped
6.6
Median CVSS
What it is

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.

Recent examples
7.8cvss
CVE-2026-85028

CVE-2026-85028 - HIGH Severity Vulnerability

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4.

HIGHno explanation yet
0%
epss
none
CVE-2026-82346

CVE-2026-82346 - UNKNOWN Severity Vulnerability

A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

no explanation yet
0%
epss
6.6cvss
CVE-2026-63693

CVE-2026-63693 - MEDIUM Severity Vulnerability

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-379
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)