VariantIncomplete

CWE-556ASP.NET Misconfiguration: Use of Identity Impersonation

Category: config

Description

Configuring an ASP.NET application to run with impersonated credentials may give the application unnecessary privileges. The use of impersonated credentials allows an ASP.NET application to run with either the privileges of the client on whose behalf it is executing or with arbitrary privileges granted in its configuration.

Common consequences· 1

  • Access Control — Gain Privileges or Assume Identity

Potential mitigations· 1

  • [Architecture and Design]Use the least privilege principle.

References

  1. https://cwe.mitre.org/data/definitions/556.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
.NET Misconfiguration: Use of Impersonation
CWE
ASP.NET Misconfiguration: Password in Configuration File
CWE
ASP.NET Misconfiguration: Missing Custom Error Page
CWE
ASP.NET Misconfiguration: Not Using Input Validation Framework
CWE
ASP.NET Misconfiguration: Improper Model Validation
CVE
CVE-2026-45490
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.