CWE · MITRE source
CWE-276Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 8 mapping(s) from 5 framework(s): STIG windows server 2016 2 (mostly) · STIG windows server 2019 2 (mostly) · STIG windows server 2022 2 (mostly) · CAPEC 1 (partial) · ATT&CK 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 11 hardening rules · 3 OS baselines
—
NIST 800-53 r5 controls that address this weakness (11)AI-assisted
Showing the 10 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
CM-1 | Policy and Procedures | CM | Establishes requirements for appropriate default permissions on system resources as part of configuration management. |
CM-2 | Baseline Configuration | CM | Baseline establishment and updates on install/upgrade ensure correct default permissions rather than insecure ones. |
CM-6 | Configuration Settings | CM | Requiring the most restrictive settings instead of defaults prevents incorrect default permissions on resources. |
AC-1 | Policy and Procedures | AC | Access control policy can specify and enforce secure default permissions for resources. |
AC-6 | Least Privilege | AC | Guides setting of default permissions to the minimum required level. |
PL-11 | Baseline Tailoring | PL | Tailoring explicitly overrides or scopes default permission assignments in the baseline to match the system's actual risk and operational needs. |
PL-9 | Central Management | PL | A central authority can define and push correct default permissions, eliminating the common practice of leaving insecure defaults on individual hosts. |
SA-16 | Developer-provided Training | SA | Training covers proper setting of permissions on resources, reducing incorrect default or inherited permissions after deployment. |
SA-5 | System Documentation | SA | Administrator documentation on secure configuration and default settings prevents incorrect default permissions from remaining in place. |
PE-1 | Policy and Procedures | PE | Requires addressing secure default permissions in physical and environmental protection controls. |
Show 1 more broadly-applicable controls
CM-9 | Configuration Management Plan | CM | Requires documented processes that include setting and maintaining correct default permissions for configuration items. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2013-0632 KEV UPD | 9.9 | 9.8 | 0.9369 | 2013-01-17 |
CVE-2017-11610 UPD | 9.1 | 8.8 | 0.8738 | 2017-08-23 |
CVE-2023-29919 UPD | 9.1 | 9.1 | 0.6022 | 2023-05-23 |
CVE-2019-17124 UPD | 8.6 | 9.8 | 0.2254 | 2019-10-09 |
CVE-2021-3437 UPD | 8.4 | 9.8 | 0.1555 | 2022-12-12 |
CVE-2024-57684 UPD | 8.4 | 9.8 | 0.1436 | 2025-01-16 |
CVE-1999-0426 UPD | 8.2 | 9.8 | 0.1056 | 1999-03-01 |
CVE-2020-12834 UPD | 8.2 | 9.8 | 0.1107 | 2020-05-15 |
CVE-2022-32207 UPD | 8.0 | 9.8 | 0.0687 | 2022-07-07 |
CVE-2023-26918 UPD | 8.0 | 9.8 | 0.0605 | 2023-04-14 |
CVE-2023-31067 UPD | 8.0 | 9.8 | 0.0540 | 2023-09-11 |
CVE-2023-31068 UPD | 8.0 | 9.8 | 0.0533 | 2023-09-11 |
CVE-2020-9039 UPD | 7.9 | 9.8 | 0.0394 | 2020-02-22 |
CVE-2020-9409 UPD | 7.8 | 9.8 | 0.0342 | 2020-05-20 |
CVE-2020-13452 UPD | 7.8 | 9.8 | 0.0275 | 2021-01-07 |
CVE-2021-39274 UPD | 7.8 | 9.8 | 0.0312 | 2021-08-19 |
CVE-2021-36363 UPD | 7.8 | 9.8 | 0.0380 | 2021-09-28 |
CVE-2021-36365 UPD | 7.8 | 9.8 | 0.0380 | 2021-09-28 |
CVE-2021-45003 UPD | 7.8 | 9.8 | 0.0301 | 2022-01-10 |
CVE-2017-5642 UPD | 7.7 | 9.8 | 0.0189 | 2017-04-03 |
CVE-2019-12450 UPD | 7.7 | 9.8 | 0.0260 | 2019-05-29 |
CVE-2019-17383 UPD | 7.7 | 9.8 | 0.0231 | 2019-10-09 |
CVE-2020-29491 UPD | 7.7 | 10.0 | 0.0185 | 2021-01-04 |
CVE-2020-29492 UPD | 7.7 | 10.0 | 0.0174 | 2021-01-04 |
CVE-2019-20468 UPD | 7.7 | 9.8 | 0.0230 | 2021-02-01 |