ClassDraftTop 25 #15
CWE-269Improper Privilege Management
Category: authz
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Common consequences· 1
- Access Control — Gain Privileges or Assume Identity
Potential mitigations· 3
- [Architecture and Design, Operation]Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- [Architecture and Design]Follow the principle of least privilege when assigning access rights to entities in a software system.
- [Architecture and Design]Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
Related CAPEC attack patterns· 3
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Restful Privilege Elevationcapec-58 | 100% | live |
| AttackPattern | Privilege Escalationcapec-233 | 100% | live |
Compliance frameworks addressing this (incoming)32
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | pci_dss_v4-r11 | 100% | live |
| ComplianceControl | ai_act-art10 | 100% | live |
| ComplianceControl | cis_v8-18 | 100% | live |
| ComplianceControl | owasp_top10-a01 | 100% | live |
| ComplianceControl | iso27001-a.8.25 | 100% | live |
| ComplianceControl | gdpr-art35 | 100% | live |
| ComplianceControl | dora-art10 | 100% | live |
| ComplianceControl | iso27001-a.5.23 | 100% | live |
| ComplianceControl | dora-art17 | 100% | live |
| ComplianceControl | owasp_api_top10-api05 | 100% | live |
| ComplianceControl | dora-art9 | 100% | live |
| ComplianceControl | pci_dss_v4-r2 | 100% | live |
| ComplianceControl | gdpr-art25 | 100% | live |
| ComplianceControl | nis2-art21f | 100% | live |
| ComplianceControl | nis2-art21i | 100% | live |
| ComplianceControl | gdpr-art34 | 100% | live |
| ComplianceControl | iso27001-a.8.2 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm06 | 100% | live |
| ComplianceControl | cis_v8-2 | 100% | live |
| ComplianceControl | gdpr-art32 | 100% | live |
| ComplianceControl | pci_dss_v4-r7 | 100% | live |
| ComplianceControl | pci_dss_v4-r5 | 100% | live |
| ComplianceControl | cis_v8-6 | 100% | live |
| ComplianceControl | cis_v8-5 | 100% | live |
| ComplianceControl | nis2-art21a | 100% | live |
| ComplianceControl | iso27701-a.7.3.6 | 100% | live |
| ComplianceControl | tiber_eu-closure | 100% | live |
| ComplianceControl | ai_act-art15 | 100% | live |
| ComplianceControl | tiber_eu-testing | 100% | live |
| ComplianceControl | cis_v8-4 | 100% | live |
Showing top 30 of 32 by confidence. Click any target to see the full neighbourhood.
(incoming)116
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-0177cve-2025-0177 | 0% | live |
| Vulnerability | CVE-2025-0180cve-2025-0180 | 0% | live |
| Vulnerability | CVE-2025-0358cve-2025-0358 | 0% | live |
| Vulnerability | CVE-2025-0505cve-2025-0505 | 0% | live |
| Vulnerability | CVE-2025-11086cve-2025-11086 | 0% | live |
| Vulnerability | CVE-2025-11168cve-2025-11168 | 0% | live |
| Vulnerability | CVE-2025-11457cve-2025-11457 | 0% | live |
| Vulnerability | CVE-2025-11533cve-2025-11533 | 0% | live |
| Vulnerability | CVE-2025-11561cve-2025-11561 | 0% | live |
| Vulnerability | CVE-2025-11923cve-2025-11923 | 0% | live |
| Vulnerability | CVE-2025-12424cve-2025-12424 | 0% | live |
| Vulnerability | CVE-2025-12485cve-2025-12485 | 0% | live |
| Vulnerability | CVE-2025-12882cve-2025-12882 | 0% | live |
| Vulnerability | CVE-2025-1295cve-2025-1295 | 0% | live |
| Vulnerability | CVE-2025-12981cve-2025-12981 | 0% | live |
| Vulnerability | CVE-2025-13534cve-2025-13534 | 0% | live |
| Vulnerability | CVE-2025-13538cve-2025-13538 | 0% | live |
| Vulnerability | CVE-2025-13540cve-2025-13540 | 0% | live |
| Vulnerability | CVE-2025-13542cve-2025-13542 | 0% | live |
| Vulnerability | CVE-2025-13559cve-2025-13559 | 0% | live |
| Vulnerability | CVE-2025-13563cve-2025-13563 | 0% | live |
| Vulnerability | CVE-2025-13618cve-2025-13618 | 0% | live |
| Vulnerability | CVE-2025-13619cve-2025-13619 | 0% | live |
| Vulnerability | CVE-2025-13675cve-2025-13675 | 0% | live |
| Vulnerability | CVE-2025-13680cve-2025-13680 | 0% | live |
| Vulnerability | CVE-2025-13764cve-2025-13764 | 0% | live |
| Vulnerability | CVE-2025-13787cve-2025-13787 | 0% | live |
| Vulnerability | CVE-2025-13851cve-2025-13851 | 0% | live |
| Vulnerability | CVE-2025-14533cve-2025-14533 | 0% | live |
| Vulnerability | CVE-2025-14736cve-2025-14736 | 0% | live |
Showing top 30 of 116 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.