← Vulnerability feed

Vulnerability record · CVE-2025-5199 · published 12 July 2025

CVE-2025-5199: Canonical multipass incorrect default permissions vulnerability

Canonical · Multipass

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.

7.8 CVSS 3.1 High EPSS 0.15% · top 96.1% CWE-276 · Incorrect default permissionsCWE-863 · Incorrect authorization
7.8CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-5199 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-3626Canonical multipass improper access control vulnerabilityThe Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the ope…EPSS 0.25%8.4CVE-2026-49238Canonical multipass path traversal vulnerabilityAn issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root pr…EPSS 0.45%7.8CVE-2026-49237Canonical multipass incorrect default permissions vulnerabilityAn issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version…EPSS 0.16%7.8CVE-2021-3747Canonical multipass incorrect permission assignment vulnerabilityThe MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.EPSS 0.25%7.8CVE-2026-87886Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalationAcronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escal…KEVEPSS 0.23%analysed6.5CVE-2022-22948VMware vCenter Server information disclosure via incorrect file permissionsvCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because …KEVEPSS 13%analysed9.8CVE-2013-0632Adobe ColdFusion RDS default password authentication bypassAdobe ColdFusion 9.0 through 10 ships administrator.cfc with an RDS component that accepts a default empty password. An attacker can log in to RDS wi…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2025-5199), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.