CWE-277: Insecure Inherited Permissions
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
49 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-20008 — Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a pr
- CVE-2026-7891 — The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization
- CVE-2025-64185 — Open OnDemand RPM packages create world writable locations
- CVE-2025-22448 — Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an a
- CVE-2025-29982 — Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low p
- CVE-2025-3473 — IBM Security Guardium privilege escalation
- CVE-2025-32092 — Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Appli
- CVE-2025-24327 — Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ri
- CVE-2025-20629 — Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before v
- CVE-2024-51448 — IBM Robotic Process Automation privilege escalation
- CVE-2024-36294 — Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user t
- CVE-2024-36276 — Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user t
- CVE-2024-23908 — Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may a
- CVE-2025-31332 — Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform
- CVE-2025-36104 — IBM Storage Scale information disclosure
- CVE-2026-9046 — A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications
- CVE-2025-32797 — Conda-build Insecure Build Script Permissions Enabling Arbitrary Code Execution
- CVE-2025-9039 — Information Disclosure in Amazon ECS Container Agent
- CVE-2025-65111 — SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
Recently published
- CVE-2026-9046 — A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications
- CVE-2026-7891 — The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization
- CVE-2025-32092 — Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Appli
- CVE-2025-65111 — SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
- CVE-2025-64185 — Open OnDemand RPM packages create world writable locations
- CVE-2025-24327 — Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ri
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-9039 — Information Disclosure in Amazon ECS Container Agent
- CVE-2025-36104 — IBM Storage Scale information disclosure
- CVE-2025-32797 — Conda-build Insecure Build Script Permissions Enabling Arbitrary Code Execution
- CVE-2025-3473 — IBM Security Guardium privilege escalation
- CVE-2025-22448 — Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an a
- CVE-2025-20629 — Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before v
- CVE-2025-20008 — Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a pr
- CVE-2025-31332 — Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform
- CVE-2025-29982 — Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low p
- CVE-2024-51448 — IBM Robotic Process Automation privilege escalation
- CVE-2024-36294 — Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user t
- CVE-2024-36276 — Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user t
- CVE-2024-23908 — Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may a