CWE-378
CWE-378 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-378, highest CVSS first.
- HIGH 8.8CVE-2026-25265
Privilege escalation due to weak configuration while temporary file handling.
software center · windows
- LOW 3.9CVE-2026-97026public PoC
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runt…
- LOW 3.2CVE-2026-97025public PoC
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI rep…