# CWE-552: Files or Directories Accessible to External Parties

**KEV-linked**

> As of 2026-10-10, CWE-552 (Files or Directories Accessible to External Parties) underlies 5 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 13 tracked threats.

**Last updated:** 2026-10-10

## What is CWE-552?

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Web servers, FTP servers, and similar servers may store a set of files underneath a "root" directory that is accessible to the server's users. Applications may store sensitive files underneath this root without also using access control to limit which users may request those files, if any. Alternately, an application might package multiple files or directories into an archive file (e.g., ZIP or tar), but the application might not exclude sensitive files that are underneath those directories. In cloud technologies and containers, this weakness might present itself in the form of misconfigured storage accounts that can be read or written by a public or anonymous user.

CWE-552 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific; Cloud Computing.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/552.html) (CWE-552 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality, Integrity** — Read Files or Directories, Modify Files or Directories

_Source: MITRE CWE, common consequences._

## How CWE-552 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-552, published between 2025-10-09 and 2026-10-05. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 2 medium. The highest EPSS score in the set is 92.1% (CVE-2025-11371), the modelled probability of exploitation in the next 30 days. 13 tracked threats reference CWE-552 directly or through a CVE it covers; the most recent is “Cl0p Ransomware MFT Attack Pattern: Multi-Year Zero-Day Campaigns Against File Transfer and Enterprise Software (2020-2025)” (2026-10-09). Affected products concentrate in Apache Software Foundation (1), Atlassian (1), Gladinet (1), among 5 vendors in total.

## Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-552, CISA KEV first, then by CVSS score.

- [CVE-2025-11371](https://intel.threadlinqs.com/cve/CVE-2025-11371) — CISA KEV · CVSS 7.5 high · EPSS 92.1% · published 2025-10-09
- [CVE-2026-57990](https://intel.threadlinqs.com/cve/CVE-2026-57990) — CVSS 7.4 high · published 2026-07-26
- [CVE-2026-105750](https://intel.threadlinqs.com/cve/CVE-2026-105750) — CVSS 5.9 medium · EPSS 0.3% · published 2026-10-05
- [CVE-2026-58415](https://intel.threadlinqs.com/cve/CVE-2026-58415) — CVSS 5.3 medium · EPSS 0.5% · published 2026-10-01
- [CVE-2026-21589](https://intel.threadlinqs.com/cve/CVE-2026-21589) — EPSS 0.7% · published 2026-10-05

## Affected vendors

- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation) — 1 CVE
- [Atlassian](https://intel.threadlinqs.com/vendors/atlassian) — 1 CVE
- **Gladinet** — 1 CVE
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- **docling-project** — 1 CVE

## Threat activity

13 tracked threats cite CWE-552:

- [Cl0p Ransomware MFT Attack Pattern: Multi-Year Zero-Day Campaigns Against File Transfer and Enterprise Software (2020-2025)](https://intel.threadlinqs.com/threat/TL-2026-3070) — HIGH · 2026-10-09
- [Atlassian Data Center critical unauthenticated arbitrary file access vulnerability (CVE-2026-21589) across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye](https://intel.threadlinqs.com/threat/TL-2026-2966) — CRITICAL · 2026-10-06
- [Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)](https://intel.threadlinqs.com/threat/TL-2026-2876) — MEDIUM · 2026-10-02
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH · 2026-09-15
- [Synology MailPlus Server Critical Remote Code Execution and Arbitrary File Access (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135)](https://intel.threadlinqs.com/threat/TL-2026-1014) — CRITICAL · 2026-06-30
- [Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com / wetransfer\[.\]ICU SEO-Poisoning Operation)](https://intel.threadlinqs.com/threat/TL-2026-0799) — HIGH · 2026-06-15
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain, RevSocks + Reverse SSH Tunnels Targeting Russian and Belarusian Government](https://intel.threadlinqs.com/threat/TL-2026-0583) — HIGH · 2026-05-25
- [Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243)](https://intel.threadlinqs.com/threat/TL-2026-0557) — HIGH · 2026-05-22
- [NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests Cloud Credentials and AI API Keys via Langflow RCE (CVE-2026-33017)](https://intel.threadlinqs.com/threat/TL-2026-0514) — HIGH · 2026-05-14
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, CVE-2025-48703)](https://intel.threadlinqs.com/threat/TL-2026-0478) — CRITICAL · 2026-05-07
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential Harvesting (Backdoor.Linux.QLNX.A)](https://intel.threadlinqs.com/threat/TL-2026-0456) — HIGH · 2026-05-04
- [Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach](https://intel.threadlinqs.com/threat/TL-2026-0425) — CRITICAL · 2026-04-27
- [Context.ai OAuth Token Compromise: SaaS Integration-Layer Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-0398) — CRITICAL · 2026-04-20

## Mitigations

- **Implementation, System Configuration, Operation**: When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-668 Exposure of Resource to Wrong Sphere](https://intel.threadlinqs.com/cwe/CWE-668)
- [CWE-285 Improper Authorization](https://intel.threadlinqs.com/cwe/CWE-285)

Canonical: https://intel.threadlinqs.com/cwe/CWE-552
Source definition: https://cwe.mitre.org/data/definitions/552.html
Detection rules and IOCs for threats exploiting CWE-552 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
