CWE-269
Improper Privilege Management
AI Translation Available
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Status
draft
Abstraction
class
Likelihood
medium
Affected Platforms
Technical Details
AI Translation
Common Consequences
access control
Impacts
gain privileges or assume identity
Detection Methods
automated static analysis
Potential Mitigations
Phases:
architecture and design
operation
Descriptions:
•
Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
•
Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
•
Follow the principle of least privilege when assigning access rights to entities in a software system.