SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-276 Incorrect Default Permissions

Coverage status: Background only, this CWE is in scope but has no rules in the SiteShadow rule registry. Taint and heuristic analyzers may flag related patterns; see the coverage report and known gaps for the authoritative list.

What this means

SiteShadow flagged default permissions that are too permissive (files created world-readable/world-writable, buckets or resources opened broadly by default).

Why it matters

Excessive permissions allow unintended access to sensitive data.

Safer examples

1) Use least-privilege permissions on creation

Create files with owner-only permissions unless sharing is explicitly intended.

2) Separate public and private resources

If something must be public (static assets), keep it isolated from sensitive storage.

3) Review defaults in IaC and frameworks

Many exposures happen because defaults were accepted without review (see CLOUD01).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.