CWE · MITRE source
CWE-266Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Last updated: 22 August 2026 00:25 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 8 mapping(s) from 6 framework(s): STIG ubuntu 24 04 2 (mostly) · STIG ubuntu 22 04 2 (partial) · STIG oracle linux 8 1 (partial) · STIG oracle linux 9 1 (partial) · STIG rhel 8 1 (partial) · STIG rhel 9 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A06:2025 Insecure Design.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 8 hardening rules · 6 OS baselines
—
NIST 800-53 r5 controls that address this weakness (5)AI-assisted
Showing the 3 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
AC-1 | Policy and Procedures | AC | Designation of a manager and policy dissemination ensures privileges are assigned according to defined roles. |
AC-13 | Supervision and Review — Access Control | AC | Regular reviews catch incorrect privilege assignments to users, roles, or processes. |
AC-2 | Account Management | AC | Explicitly specifying privileges and group/role memberships for accounts reduces the risk of incorrect privilege assignments. |
Show 2 more broadly-applicable controls
AC-5 | Separation of Duties | AC | The control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement. |
AC-6 | Least Privilege | AC | Ensures privileges are assigned only as necessary rather than incorrectly over-granted. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2026-48172 KEV UPD | 9.9 | 9.8 | 0.1891 | 2026-05-21 |
CVE-2024-28000 UPD | 9.8 | 9.8 | 0.6827 | 2024-08-21 |
CVE-2025-27007 UPD | 9.4 | 9.8 | 0.5148 | 2025-05-01 |
CVE-2025-47539 UPD | 8.9 | 9.8 | 0.3320 | 2025-05-23 |
CVE-2026-23550 UPD | 8.6 | 9.8 | 0.2063 | 2026-01-14 |
CVE-2025-41115 UPD | 8.5 | 10.0 | 0.1691 | 2025-11-21 |
CVE-2022-20759 UPD | 8.1 | 8.8 | 0.2922 | 2022-05-03 |
CVE-2025-49388 UPD | 8.0 | 9.8 | 0.0538 | 2025-08-28 |
CVE-2024-24882 UPD | 7.7 | 9.8 | 0.0211 | 2024-05-17 |
CVE-2024-54363 UPD | 7.7 | 9.8 | 0.0189 | 2024-12-16 |
CVE-2024-50485 UPD | 7.5 | 9.8 | 0.0098 | 2024-10-29 |
CVE-2024-54383 UPD | 7.5 | 9.8 | 0.0114 | 2024-12-18 |
CVE-2025-10644 | 7.5 | 9.4 | 0.0300 | 2025-09-17 |
CVE-2023-1174 UPD | 7.4 | 9.8 | 0.0076 | 2023-05-24 |
CVE-2024-2409 UPD | 7.4 | 9.8 | 0.0083 | 2024-03-29 |
CVE-2024-43153 UPD | 7.4 | 9.8 | 0.0062 | 2024-08-13 |
CVE-2024-8253 UPD | 7.4 | 8.8 | 0.0937 | 2024-09-11 |
CVE-2024-9863 UPD | 7.4 | 9.8 | 0.0060 | 2024-10-17 |
CVE-2024-54293 UPD | 7.4 | 9.8 | 0.0062 | 2024-12-13 |
CVE-2024-56071 UPD | 7.4 | 9.8 | 0.0062 | 2024-12-31 |
CVE-2024-56205 UPD | 7.4 | 9.8 | 0.0062 | 2024-12-31 |
CVE-2024-56040 UPD | 7.4 | 9.8 | 0.0076 | 2024-12-31 |
CVE-2024-56043 UPD | 7.4 | 9.8 | 0.0063 | 2024-12-31 |
CVE-2024-12470 UPD | 7.4 | 9.8 | 0.0064 | 2025-01-07 |
CVE-2024-13421 UPD | 7.4 | 9.8 | 0.0076 | 2025-02-12 |