CWE-378: Creation of Temporary File With Insecure Permissions
Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.
43 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-39872 — A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application
- CVE-2025-32438 — Local privilege escalation in make-initrd-ng
- CVE-2025-27148 — Gradle vulnerable to local privilege escalation through system temporary directory
- CVE-2025-34352 — JumpCloud Remote Assist < 0.317.0 Arbitrary File Write/Delete via Insecure Temp Directory
- CVE-2025-38747 — Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio
- CVE-2025-46685 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
- CVE-2026-4822 — Enter Software Iperius Backup Backup Service temp file
- CVE-2025-7647 — Insecure Temporary File Handling in run-llama/llama_index
- CVE-2025-46684 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
- CVE-2024-52543 — Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A
- CVE-2025-4953 — Podman: build context bind mount
- CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
- CVE-2026-33572 — OpenClaw < 2026.2.17 - Insufficient File Permissions in Session Transcript Files
- CVE-2026-2817 — Spring Data Geode Insecure Temporary Directory Usage
- CVE-2025-9474 — Mihomo Party Socket sysproxy.ts enableSysProxy temp file
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2024-47884 — Insecure Temporary File in `foxmarks`
- CVE-2024-23454 — Apache Hadoop: Temporary File Local Information Disclosure
Recently published
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
- CVE-2026-33572 — OpenClaw < 2026.2.17 - Insufficient File Permissions in Session Transcript Files
- CVE-2026-4822 — Enter Software Iperius Backup Backup Service temp file
- CVE-2026-2817 — Spring Data Geode Insecure Temporary Directory Usage
- CVE-2025-46685 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
- CVE-2025-46684 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
- CVE-2025-34352 — JumpCloud Remote Assist < 0.317.0 Arbitrary File Write/Delete via Insecure Temp Directory
- CVE-2025-7647 — Insecure Temporary File Handling in run-llama/llama_index
- CVE-2025-4953 — Podman: build context bind mount
- CVE-2025-9474 — Mihomo Party Socket sysproxy.ts enableSysProxy temp file
- CVE-2025-38747 — Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio
- CVE-2025-32438 — Local privilege escalation in make-initrd-ng
- CVE-2025-27148 — Gradle vulnerable to local privilege escalation through system temporary directory
- CVE-2024-52543 — Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A
- CVE-2024-47884 — Insecure Temporary File in `foxmarks`
- CVE-2024-23454 — Apache Hadoop: Temporary File Local Information Disclosure
- CVE-2024-39872 — A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application