CWE-286 — Incorrect User Management
CWE-286: Incorrect User Management
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Class |
| Status | Incomplete |
| Likelihood of exploit | — |
Description
The product does not properly manage a user within its environment.
Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.
Common consequences
- Other: Varies by Context
Mitigations
(none listed)
References
- CWE page: https://cwe.mitre.org/data/definitions/286.html
- CWE list: https://cwe.mitre.org/data/index.html
See all 1,245 pages under Weakness classes (CWE) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.