What is CWE-266?
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Analyzing data...
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Analyzing data...
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Impact | Scope | Explanation |
|---|---|---|
| Gain Privileges or Assume Identity | Access Control | A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts. |
Below are representative vulnerabilities related to this CWE, prioritized by severity.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScanen