CWE-276: Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Overview
CWE-276 (Incorrect Default Permissions) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
861 recorded CVEs are caused by CWE-276 (Incorrect Default Permissions), including 2 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 79 new CWE-276 CVEs have been recorded so far in 2026 (211 in 2025).