CWE-278: Insecure Preserved Inherited Permissions
A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.
5 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-2947 — IBM i privilege escalation
- CVE-2026-6265 — Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2
- CVE-2026-71477 — mise: Incorrect file ownership, when installed by the root user using `install.sh`
- CVE-2024-38531 — Nix sandbox escape
Recently published
- CVE-2026-71477 — mise: Incorrect file ownership, when installed by the root user using `install.sh`
- CVE-2026-6265 — Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2
- CVE-2025-2947 — IBM i privilege escalation
- CVE-2024-38531 — Nix sandbox escape