SiteShadow
Back to vulnerability library

CWE-276 Incorrect Default Permissions

What this means

SiteShadow flagged default permissions that are too permissive (files created world-readable/world-writable, buckets or resources opened broadly by default).

Why it matters

Excessive permissions allow unintended access to sensitive data.

Safer examples

1) Use least-privilege permissions on creation

Create files with owner-only permissions unless sharing is explicitly intended.

2) Separate public and private resources

If something must be public (static assets), keep it isolated from sensitive storage.

3) Review defaults in IaC and frameworks

Many exposures happen because defaults were accepted without review (see CLOUD01).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Request access View coverage