CWE-378

CWE-378 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-378, highest CVSS first.

  1. HIGH 8.8CVE-2026-25265

    Privilege escalation due to weak configuration while temporary file handling.

    software center · windows

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.9CVE-2026-97026public PoC

    Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runt…

    AI risk analysis on Exploit-DB.ai →

  3. LOW 3.2CVE-2026-97025public PoC

    Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI rep…

    AI risk analysis on Exploit-DB.ai →