CWE-379: Creation of Temporary File in Directory with Insecure Permissions
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.
63 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-32438 — Local privilege escalation in make-initrd-ng
- CVE-2025-27148 — Gradle vulnerable to local privilege escalation through system temporary directory
- CVE-2024-9950 — Abuse of Unauthenticated Compliance Recheck in SecureConnector
- CVE-2024-9500 — Autodesk ADP Desktop SDK Privilege Escalation Vulnerability
- CVE-2026-14551 — Local Privilege Escalation in servereye client (sensorhub)
- CVE-2024-24693 — Zoom Rooms Client for Windows - Improper Access Control
- CVE-2025-10279 — Privilege Escalation in mlflow/mlflow
- CVE-2025-71176 — pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users
- CVE-2026-12555 — HP Easy Start for macOS - Security Update
- CVE-2025-32802 — Insecure handling of file paths allows multiple local attacks
- CVE-2026-85028 — Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
- CVE-2026-7539 — HP Dock Accessory WMI Provider Installer Security Update
- CVE-2026-54328 — Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
- CVE-2026-82346 — HP ImageDiags - Potential Escalation of Privilege
- CVE-2019-25677 — WinRAR 5.61 Denial of Service via Malformed Language File
- CVE-2026-63693 — Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile
- CVE-2025-64896 — Creative Cloud Desktop | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379)
- CVE-2025-21162 — Photoshop Elements | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379)
- CVE-2026-42191 — OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter
- CVE-2026-50544 — NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions
Recently published
- CVE-2026-85028 — Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
- CVE-2026-82346 — HP ImageDiags - Potential Escalation of Privilege
- CVE-2026-63693 — Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile
- CVE-2026-12555 — HP Easy Start for macOS - Security Update
- CVE-2026-50544 — NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions
- CVE-2026-14551 — Local Privilege Escalation in servereye client (sensorhub)
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-7539 — HP Dock Accessory WMI Provider Installer Security Update
- CVE-2026-54328 — Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
- CVE-2026-42191 — OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter
- CVE-2019-25677 — WinRAR 5.61 Denial of Service via Malformed Language File
- CVE-2026-2817 — Spring Data Geode Insecure Temporary Directory Usage
- CVE-2025-10279 — Privilege Escalation in mlflow/mlflow
- CVE-2025-71176 — pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users
- CVE-2025-64896 — Creative Cloud Desktop | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379)
- CVE-2025-33111 — IBM Controller Information Disclosure
- CVE-2025-32802 — Insecure handling of file paths allows multiple local attacks
- CVE-2025-32438 — Local privilege escalation in make-initrd-ng
- CVE-2025-27148 — Gradle vulnerable to local privilege escalation through system temporary directory
- CVE-2025-21162 — Photoshop Elements | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379)