The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Volume of CVEs assigned to CWE-281 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
337 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8543CRITICAL Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, | Jun 15, 2017 | 9.8 | 93 | YES | NO |
CVE-2019-0233HIGH An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload. | Sep 14, 2020 | 7.5 | 63 | NO | NO |
CVE-2021-33990CRITICAL Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference li | Apr 16, 2023 | 9.8 | 48 | NO | YES |
CVE-2017-8589CRITICAL Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 | Jul 11, 2017 | 9.8 | 45 | NO | NO |
CVE-2026-39832CRITICAL When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently st | May 22, 2026 | 9.1 | 42 | NO | NO |
CVE-2026-39828HIGH When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restri | May 22, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-23556CRITICAL When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.
When the domain ID is eventually reused, the new domain can create fewer
nod | Jul 9, 2026 | 9.4 | 39 | NO | NO |
CVE-2024-46310CRITICAL Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint | Jan 13, 2025 | 9.1 | 39 | NO | YES |
CVE-2026-24834HIGH Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an | Feb 19, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-44832HIGH Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PA | May 26, 2026 | 8.8 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.