CWE Database
/

CWE-286

Back to CWE list

CWE-286

Incorrect User Management

Class
Incomplete

Description

The product does not properly manage a user within its environment.

Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.

Parent Weaknesses (ChildOf)

Common Consequences

Scope

Other

Impact

Varies by Context

CVE-2022-36109

Containerization product does not record a user's supplementary group ID, allowing bypass of group restrictions.

CVE-1999-1193

Operating system assigns user to privileged wheel group, allowing the user to gain root privileges.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now