VariantDraft
CWE-277Insecure Inherited Permissions
Category: authz
Description
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
Common consequences· 1
- Confidentiality / Integrity — Read Application Data, Modify Application Data
Potential mitigations· 2
- [Architecture and Design, Operation]Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- [Architecture and Design]
References
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-11554cve-2025-11554 | 0% | live |
| Vulnerability | CVE-2025-58437cve-2025-58437 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.