Cyber Resilience

CWE · MITRE source

CWE-266Incorrect Privilege Assignment

Abstraction: Base · CVEs in our corpus: 1,082

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Last updated: 22 August 2026 00:25 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 8 mapping(s) from 6 framework(s): STIG ubuntu 24 04 2 (mostly) · STIG ubuntu 22 04 2 (partial) · STIG oracle linux 8 1 (partial) · STIG oracle linux 9 1 (partial) · STIG rhel 8 1 (partial) · STIG rhel 9 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A06:2025 Insecure Design.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AC-1 Policy and Procedures
  • AC-13 Supervision and Review — Access Control
  • AC-2 Account Management
  • AC-5 Separation of Duties
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 8 hardening rules · 6 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (5)AI-assisted

Showing the 3 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
AC-1Policy and ProceduresACDesignation of a manager and policy dissemination ensures privileges are assigned according to defined roles.
AC-13Supervision and Review — Access ControlACRegular reviews catch incorrect privilege assignments to users, roles, or processes.
AC-2Account ManagementACExplicitly specifying privileges and group/role memberships for accounts reduces the risk of incorrect privilege assignments.
Show 2 more broadly-applicable controls
AC-5Separation of DutiesACThe control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement.
AC-6Least PrivilegeACEnsures privileges are assigned only as necessary rather than incorrectly over-granted.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-48172 KEV 9.99.80.18912026-05-21
CVE-2024-28000 9.89.80.68272024-08-21
CVE-2025-27007 9.49.80.51482025-05-01
CVE-2025-47539 8.99.80.33202025-05-23
CVE-2026-23550 8.69.80.20632026-01-14
CVE-2025-41115 8.510.00.16912025-11-21
CVE-2022-20759 8.18.80.29222022-05-03
CVE-2025-49388 8.09.80.05382025-08-28
CVE-2024-24882 7.79.80.02112024-05-17
CVE-2024-54363 7.79.80.01892024-12-16
CVE-2024-50485 7.59.80.00982024-10-29
CVE-2024-54383 7.59.80.01142024-12-18
CVE-2025-106447.59.40.03002025-09-17
CVE-2023-1174 7.49.80.00762023-05-24
CVE-2024-2409 7.49.80.00832024-03-29
CVE-2024-43153 7.49.80.00622024-08-13
CVE-2024-8253 7.48.80.09372024-09-11
CVE-2024-9863 7.49.80.00602024-10-17
CVE-2024-54293 7.49.80.00622024-12-13
CVE-2024-56071 7.49.80.00622024-12-31
CVE-2024-56205 7.49.80.00622024-12-31
CVE-2024-56040 7.49.80.00762024-12-31
CVE-2024-56043 7.49.80.00632024-12-31
CVE-2024-12470 7.49.80.00642025-01-07
CVE-2024-13421 7.49.80.00762025-02-12