A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.
Volume of CVEs assigned to CWE-278 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6265HIGH Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1 | Apr 27, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-2947CRITICAL IBM i 7.6
contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain r | Apr 17, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-36538HIGH Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-37769HIGH Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request. | Jul 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-38497HIGH Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when e | Aug 4, 2023 | 7.3 | 23 | NO | NO |
Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of t | Jun 28, 2024 | 3.6 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.