CWE-286

Incorrect User Management
AI Translation Available

The product does not properly manage a user within its environment.

Status
incomplete
Abstraction
class

Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.

Common Consequences

other
Impacts
varies by context

Potential Mitigations