CVE-2026-4793
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files
CVSS
7.3
Alto
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Publicado: 3 ago 2026 · Última mod.: 3 ago 2026 · CWE-276
0.1%EPSS · 30 días0.1%
2026-08-032026-08-10
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-487905.5 MED—
———Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any other local UID on the host can read the file and recover the platform JWT, which grants full Turso platform access scoped to the user's organizations. Version 1.0.26 patches the issue.12hCVE-2026-591197.3 ALT—
———Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.1hCVE-2026-21074—1.1%
——0Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.1dCVE-2026-398757.8 ALT6.3%
——2A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.7dCVE-2026-398747.8 ALT1.5%
——0A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.14dCVE-2026-174978.3 ALT37.3%
——11NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.15d