Back to Labs
Weakness (CWE)

CWE-266

Incorrect Privilege Assignment

About

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Common consequences

  • Access Control → Gain Privileges or Assume Identity

Mitigations

  • Architecture and Design, Operation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
  • Architecture and Design, Operation: Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications r

CVEs with this weakness

Frequently asked questions

What is CWE-266?

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. Common consequences Access Control → Gain Privileges or Assume Identity Mitigations Architecture and Design, Operation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.

How many CVEs does Rainforest track for CWE-266?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-266. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.