CWE-281: Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
111 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-7346 — Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create
- CVE-2025-34298 — Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation
- CVE-2025-24337 — WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
- CVE-2026-23556 — oxenstored keeps quota related use counts across domain destruction
- CVE-2026-44832 — Snipe-IT: Privilege Escalation via API Permissions Assignment
- CVE-2024-23464 — Zscaler bypass with administrative privileges on Windows
- CVE-2025-43026 — HP Support Assistant – Potential Escalation of Privilege
- CVE-2025-37735 — Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being
- CVE-2026-24194 — NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improp
- CVE-2026-35385 — In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e
- CVE-2026-40767 — WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
- CVE-2024-22121 — Zabbix Agent MSI Installer Allows Non-Admin User to Access Change Option via msiexec.exe
- CVE-2026-88016 — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
- CVE-2026-44947 — Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
- CVE-2024-43784 — Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to it's deletion
- CVE-2026-35350 — uutils coreutils cp Unexpected Privileged Executable Creation with -p
- CVE-2025-27247 — Pasteboard has an improper preservation of permissions vulnerability
- CVE-2025-26691 — telephony_call_manager has an improper preservation of permissions vulnerability
- CVE-2024-22405 — XADMaster may not apply quarantine attribute correctly to extracted files
- CVE-2026-58494 — Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
Recently published
- CVE-2026-88016 — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2025-14779 — Improper Access Control via Secret Type Management API in WSO2 Identity Server
- CVE-2026-23556 — oxenstored keeps quota related use counts across domain destruction
- CVE-2026-58494 — Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
- CVE-2026-4360 — Tarfile.extract() doesn't fully respect filter parameter
- CVE-2026-44947 — Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
- CVE-2026-40767 — WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
- CVE-2024-47270 — Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station befo
- CVE-2026-44832 — Snipe-IT: Privilege Escalation via API Permissions Assignment
- CVE-2026-24194 — NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improp
- CVE-2026-34744 — MantisBT authorization bypass allows continued access to self-uploaded attachments on private issues
- CVE-2026-34600 — Joplin Server delta API returns note content after share access is revoked
- CVE-2026-25850 — filemanagement_storage_service has an improper preservation of permissions vulnerability
- CVE-2025-8325 — Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations
- CVE-2026-35361 — uutils coreutils mknod Security Label Inconsistency and Broken Cleanup on SELinux Systems
- CVE-2026-35351 — uutils coreutils mv Silent Ownership Loss in Cross-Device Operations
- CVE-2026-35350 — uutils coreutils cp Unexpected Privileged Executable Creation with -p
- CVE-2026-35385 — In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e
- CVE-2025-37735 — Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being