CWE · MITRE source
CWE-281Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Last updated: 20 August 2026 14:15 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 3 mapping(s) from 2 framework(s): STIG windows server 2022 2 (partial) · STIG windows server 2019 1 (mostly)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
PS-5 | Personnel Transfer | PS | Forces removal or modification of permissions no longer required after reassignment, preventing improper preservation of old access rights. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2017-8543 KEV UPD | 9.9 | 9.8 | 0.6486 | 2017-06-15 |
CVE-2017-8589 UPD | 8.7 | 9.8 | 0.2616 | 2017-07-11 |
CVE-2019-0233 UPD | 8.3 | 7.5 | 0.6805 | 2020-09-14 |
CVE-2021-33990 UPD | 8.3 | 9.8 | 0.1192 | 2023-04-16 |
CVE-2018-4115 UPD | 7.7 | 9.8 | 0.0225 | 2018-04-03 |
CVE-2020-18890 UPD | 7.6 | 9.8 | 0.0152 | 2021-05-06 |
CVE-2021-29971 UPD | 7.5 | 9.8 | 0.0102 | 2021-08-05 |
CVE-2020-36070 UPD | 7.5 | 9.8 | 0.0108 | 2023-04-26 |
CVE-2023-47463 UPD | 7.5 | 9.8 | 0.0128 | 2023-11-30 |
CVE-2024-54465 UPD | 7.5 | 9.8 | 0.0088 | 2024-12-12 |
CVE-2024-56973 UPD | 7.5 | 9.8 | 0.0090 | 2025-02-14 |
CVE-2023-28668 UPD | 7.4 | 9.8 | 0.0083 | 2023-04-02 |
CVE-2023-34034 UPD | 7.4 | 9.1 | 0.0398 | 2023-07-19 |
CVE-2024-36532 UPD | 7.4 | 10.0 | 0.0045 | 2024-06-21 |
CVE-2024-41644 | 7.4 | 9.8 | 0.0068 | 2024-12-06 |
CVE-2024-41645 | 7.4 | 9.8 | 0.0068 | 2024-12-06 |
CVE-2024-41646 | 7.4 | 9.8 | 0.0068 | 2024-12-06 |
CVE-2024-41649 | 7.4 | 9.8 | 0.0068 | 2024-12-06 |
CVE-2024-55507 UPD | 7.4 | 9.8 | 0.0061 | 2025-01-03 |
CVE-2024-46622 UPD | 7.4 | 9.8 | 0.0059 | 2025-01-06 |
CVE-2024-41648 | 7.3 | 9.8 | 0.0048 | 2024-12-06 |
CVE-2024-41650 | 7.3 | 9.8 | 0.0047 | 2024-12-06 |
CVE-2024-46310 UPD | 7.3 | 9.1 | 0.0248 | 2025-01-13 |
CVE-2025-55130 UPD | 7.2 | 9.1 | 0.0166 | 2026-01-20 |
CVE-2020-10083 UPD | 7.1 | 9.1 | 0.0108 | 2020-03-13 |