CWE•Class•Draft•20 recent CVEs
CWE-269Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Common consequences
- Access Control→Gain Privileges or Assume Identity
Potential mitigations
- Architecture and Design,OperationVery carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- Architecture and DesignFollow the principle of least privilege when assigning access rights to entities in a software system.
- Architecture and DesignConsider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-905237.32026-09-13CVE-2026-905016.32026-09-13CVE-2026-887645.42026-09-13CVE-2026-864067.52026-09-13CVE-2026-800717.22026-09-13CVE-2026-904874.32026-09-12CVE-2026-154518.82026-09-12CVE-2026-877598.82026-09-12CVE-2026-856819.82026-09-12CVE-2026-777527.22026-09-12CVE-2026-859792026-09-11CVE-2026-749257.22026-09-11CVE-2026-879588.12026-09-10CVE-2026-757778.82026-09-10CVE-2026-93276.32026-09-10CVE-2026-888918.32026-09-10CVE-2026-888638.12026-09-10CVE-2026-840427.82026-09-10CVE-2026-814317.22026-09-10CVE-2026-879987.12026-09-09