CWE•Class•Draft•20 recent CVEs
CWE-269Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Common consequences
- Access Control→Gain Privileges or Assume Identity
Potential mitigations
- Architecture and Design,OperationVery carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- Architecture and DesignFollow the principle of least privilege when assigning access rights to entities in a software system.
- Architecture and DesignConsider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-149808.32026-07-30CVE-2026-126877.52026-07-30CVE-2026-179698.82026-07-30CVE-2026-179568.82026-07-30CVE-2026-179527.52026-07-30CVE-2026-179508.82026-07-30CVE-2026-178777.52026-07-30CVE-2026-178688.82026-07-30CVE-2026-178647.82026-07-30CVE-2026-178637.82026-07-30CVE-2026-178167.52026-07-30CVE-2026-121448.82026-07-29CVE-2026-181077.82026-07-28CVE-2026-159928.82026-07-28CVE-2026-143288.82026-07-28CVE-2026-145459.82026-07-28CVE-2026-660157.22026-07-27CVE-2026-663996.52026-07-27CVE-2026-131528.12026-07-27CVE-2026-123949.82026-07-27