Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-281

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337
Assigned CVEs
102nd
Commonality Rank
6.9
Avg CVSS
0.3%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-281 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2001
25 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

337 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-8543CRITICAL
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1,
Jun 15, 20179.893YESNO
CVE-2019-0233HIGH
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Sep 14, 20207.563NONO
CVE-2021-33990CRITICAL
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference li
Apr 16, 20239.848NOYES
CVE-2017-8589CRITICAL
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016
Jul 11, 20179.845NONO
CVE-2026-39832CRITICAL
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently st
May 22, 20269.142NONO
CVE-2026-39828HIGH
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restri
May 22, 20268.841NONO
CVE-2026-23556CRITICAL
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nod
Jul 9, 20269.439NONO
CVE-2024-46310CRITICAL
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
Jan 13, 20259.139NOYES
CVE-2026-24834HIGH
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an
Feb 19, 20268.836NONO
CVE-2026-44832HIGH
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PA
May 26, 20268.835NONO
View all 337 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
8%
10%
4.0-4.9
18%
19%
5.0-5.9
12%
16%
6.0-6.9
32%
26%
7.0-7.9
15%
11%
8.0-8.9
9%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.3% of CVEs· 82nd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.3% of CVEs· 79th percentile
ExploitDB
1 CVE
0.3% of CVEs· 74th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products