Threadlinqs IntelligenceStart free

Weakness · BaseCWE-552

CWE-552: Files or Directories Accessible to External Parties

KEV-linkedBase

As of 2026-10-10, CWE-552 (Files or Directories Accessible to External Parties) underlies 5 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 13 tracked threats.

CVEs
5Mapped to CWE-552
CISA KEV
1Exploited in the wild
Critical
0CVSS v3 critical CVEs
Threats
13Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-552?

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Web servers, FTP servers, and similar servers may store a set of files underneath a "root" directory that is accessible to the server's users. Applications may store sensitive files underneath this root without also using access control to limit which users may request those files, if any. Alternately, an application might package multiple files or directories into an archive file (e.g., ZIP or tar), but the application might not exclude sensitive files that are underneath those directories. In cloud technologies and containers, this weakness might present itself in the form of misconfigured storage accounts that can be read or written by a public or anonymous user.

CWE-552 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific; Cloud Computing.

Source: MITRE CWE (CWE-552 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity — Read Files or Directories, Modify Files or Directories

Source: MITRE CWE, common consequences.

How CWE-552 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-552, published between 2025-10-09 and 2026-10-05. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 2 medium. The highest EPSS score in the set is 92.1% (CVE-2025-11371), the modelled probability of exploitation in the next 30 days. 13 tracked threats reference CWE-552 directly or through a CVE it covers; the most recent is “Cl0p Ransomware MFT Attack Pattern: Multi-Year Zero-Day Campaigns Against File Transfer and Enterprise Software (2020-2025)” (2026-10-09). Affected products concentrate in Apache Software Foundation (1), Atlassian (1), Gladinet (1), among 5 vendors in total.

Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-552, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

13 tracked threats cite CWE-552:

Mitigations

  • Implementation, System Configuration, Operation: When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.