VariantIncomplete
CWE-278Insecure Preserved Inherited Permissions
Category: authz
Description
A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.
Common consequences· 1
- Confidentiality / Integrity — Read Application Data, Modify Application Data
Potential mitigations· 2
- [Architecture and Design, Operation]Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- [Architecture and Design]
References
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-2947cve-2025-2947 | 0% | live |
| Vulnerability | CVE-2026-6265cve-2026-6265 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.