Cyber Resilience

CWE · MITRE source

CWE-279Incorrect Execution-Assigned Permissions

Abstraction: Variant · CVEs in our corpus: 26

While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.

Last updated: 21 August 2026 20:21 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-05
  • PR.PS-01
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 2 hardening rules · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-37734 7.49.80.00802024-06-26
CVE-2023-4665 6.88.80.01062023-09-15
CVE-2025-58437 6.18.10.00372025-09-06
CVE-2025-14025 6.08.50.00402026-01-08
CVE-2022-21699 5.98.20.00662022-01-19
CVE-2023-4383 5.87.80.00312023-08-16
CVE-2025-30001 5.87.30.00522025-10-10
CVE-2024-11220 5.67.80.00152024-12-06
CVE-2025-23263 5.67.60.00172025-07-17
CVE-2023-50914 5.36.70.00702024-04-30
CVE-2025-22843 5.37.80.00142025-05-13
CVE-2024-25621 5.37.30.00162025-11-06
CVE-2023-3915 5.16.50.00562023-09-01
CVE-2025-12801 5.16.50.00462026-03-04
CVE-2024-37025 4.96.70.00152024-11-13
CVE-2026-200624.97.20.00122026-03-04
CVE-2025-13663 4.86.70.00102025-12-11
CVE-2020-8025 4.66.10.00472020-08-07
CVE-2025-20612 4.35.50.00222025-05-13
CVE-2026-4948 4.15.50.00122026-03-27
CVE-2017-8441 3.84.30.00732017-06-05
CVE-2026-463883.34.40.00092026-07-10
CVE-2025-26422 3.14.00.00092025-09-04
CVE-2025-362283.13.80.00212025-12-26
CVE-2025-23233 3.03.50.00212025-05-13