CWE-266: Incorrect Privilege Assignment

What is CWE-266?

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK6 — A06:2025 — Insecure Design
RELATED CVES (365 DAYS)266
ABSTRACTIONBase

Vulnerabilities mapped to CWE-266

266 vulnerabilities150.9% increase year over year

Vulnerabilities in CISA KEV for CWE-266

1 vulnerabilities

Official definition

ByMitre CWE

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Characteristics

Modes of introduction

  • Implementation: REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Common consequences

ImpactScopeExplanation
Gain Privileges or Assume IdentityAccess ControlA user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Risk mitigations

  1. Architecture and Design, OperationVery carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
  2. Environment Hardening · Architecture and Design, OperationRun your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.

Representative vulnerabilities

Sources (3)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan