Cyber Posture

CWE · MITRE source

CWE-271Privilege Dropping / Lowering Errors

Abstraction: Class · CVEs in our corpus: 11

The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.

In some contexts, a system executing with elevated permissions will hand off a process/file/etc. to another process or user. If the privileges of an entity are not reduced, then elevated privileges are spread throughout a system and possibly to an attacker.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
PS-5Personnel TransferPSMandates lowering or adjusting privileges to match new operational needs, reducing errors in privilege dropping during transfers.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-35691.77.80.02842022-10-17
CVE-2019-112431.68.10.00242019-04-22
CVE-2023-226481.68.00.00182023-06-01
CVE-2024-09851.68.00.00752024-02-08
CVE-2025-233951.67.80.00072025-05-26
CVE-2025-538191.67.90.00032025-07-14
CVE-2026-355351.57.40.00012026-04-03
CVE-2024-351791.46.80.00092024-05-15
CVE-2023-384961.26.10.00052023-07-25
CVE-2020-355131.04.90.00322021-01-26
CVE-2026-257040.00.00.00012026-03-30