Cyber Posture

CWE · MITRE source

CWE-281Improper Preservation of Permissions

Abstraction: Base · CVEs in our corpus: 321

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
PS-5Personnel TransferPSForces removal or modification of permissions no longer required after reassignment, preventing improper preservation of old access rights.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-8543 KEV9.19.80.85142017-06-15
CVE-2024-463106.89.10.83002025-01-13
CVE-2021-339905.99.80.66382023-04-16
CVE-2023-340344.79.10.47912023-07-19
CVE-2022-12273.88.80.33722022-04-29
CVE-2017-85893.79.80.28392017-07-11
CVE-2017-85632.78.10.17922017-07-11
CVE-2022-385772.68.80.14042022-09-19
CVE-2017-85782.37.80.12072017-07-11
CVE-2023-474632.29.80.04462023-11-30
CVE-2024-548802.29.10.05522025-01-06
CVE-2020-360702.19.80.02562023-04-26
CVE-2024-548792.19.10.04292025-01-06
CVE-2017-84652.07.80.06992017-06-15
CVE-2018-41152.09.80.01162018-04-03
CVE-2019-02332.07.50.07782020-09-14
CVE-2020-188902.09.80.00642021-05-06
CVE-2021-324652.08.80.03442021-08-04
CVE-2021-299712.09.80.00412021-08-05
CVE-2023-286682.09.80.00802023-04-02
CVE-2024-365322.010.00.00132024-06-21
CVE-2024-416442.09.80.00152024-12-06
CVE-2024-416452.09.80.00152024-12-06
CVE-2024-416462.09.80.00152024-12-06
CVE-2024-416482.09.80.00132024-12-06