Cyber Resilience

CWE · MITRE source

CWE-271Privilege Dropping / Lowering Errors

Abstraction: Class · CVEs in our corpus: 12

The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.

In some contexts, a system executing with elevated permissions will hand off a process/file/etc. to another process or user. If the privileges of an entity are not reduced, then elevated privileges are spread throughout a system and possibly to an attacker.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PS-5 Personnel Transfer
  • PR.AA-05
  • AC-3 Access Enforcement
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
PS-5Personnel TransferPSMandates lowering or adjusting privileges to match new operational needs, reducing errors in privilege dropping during transfers.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-44477 7.09.90.00482026-05-28
CVE-2019-11243 6.48.10.01492019-04-22
CVE-2024-0985 6.48.00.01812024-02-08
CVE-2023-22648 6.18.00.00452023-06-01
CVE-2022-3569 6.07.80.00722022-10-17
CVE-2025-23395 5.77.80.00202025-05-26
CVE-2025-53819 5.47.90.00132025-07-14
CVE-2026-35535 5.47.40.00172026-04-03
CVE-2024-35179 5.26.80.00622024-05-15
CVE-2023-38496 4.76.10.00262023-07-25
CVE-2020-35513 4.34.90.01352021-01-26