Cyber Posture

CWE · MITRE source

CWE-266Incorrect Privilege Assignment

Abstraction: Base · CVEs in our corpus: 825

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (5)AI

Showing the 3 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
AC-1Policy and ProceduresACDesignation of a manager and policy dissemination ensures privileges are assigned according to defined roles.
AC-13Supervision and Review — Access ControlACRegular reviews catch incorrect privilege assignments to users, roles, or processes.
AC-2Account ManagementACExplicitly specifying privileges and group/role memberships for accounts reduces the risk of incorrect privilege assignments.
Show 2 more broadly-applicable controls
AC-5Separation of DutiesACThe control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement.
AC-6Least PrivilegeACEnsures privileges are assigned only as necessary rather than incorrectly over-granted.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-280007.59.80.92062024-08-21
CVE-2025-270076.89.80.81472025-05-01
CVE-2024-248824.99.80.48282024-05-17
CVE-2024-221454.78.80.48862024-05-17
CVE-2024-543634.39.80.38202024-12-16
CVE-2025-475393.69.80.27902025-05-23
CVE-2024-504853.39.80.21912024-10-29
CVE-2025-341123.00.00.49682025-07-15
CVE-2022-207592.68.80.13392022-05-03
CVE-2018-10882.38.10.10782018-04-18
CVE-2024-543832.39.80.05342024-12-18
CVE-2026-235502.39.80.04852026-01-14
CVE-2019-109402.09.90.00172020-01-16
CVE-2023-11742.09.80.00092023-05-24
CVE-2024-24092.09.80.00252024-03-29
CVE-2024-357002.09.80.00632024-06-04
CVE-2024-379272.09.80.00542024-07-12
CVE-2024-431532.09.80.00732024-08-13
CVE-2024-98632.09.80.00682024-10-17
CVE-2024-492172.09.80.00302024-10-17
CVE-2024-493222.09.80.00342024-10-17
CVE-2024-524422.09.80.00202024-11-20
CVE-2024-542932.09.80.00432024-12-13
CVE-2024-542292.09.80.00242024-12-16
CVE-2024-562202.09.80.00142024-12-31