Umbra Wiki weakness weakness/CWE-286
Back to wiki

CWE-286 — Incorrect User Management

provenance: imported · CWE: CWE-286

CWE-286: Incorrect User Management

MITRE CWE weakness

Kind Weakness
Abstraction Class
Status Incomplete
Likelihood of exploit

Description

The product does not properly manage a user within its environment.

Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.

Common consequences

  • Other: Varies by Context

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/286.html
  • CWE list: https://cwe.mitre.org/data/index.html