Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Follow the principle of least privilege when assigning access rights to entities in a software system.

ChildOfCategoryCategory254Security Features
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class250Execution with Unnecessary Privileges
Development Concepts699
ParentOfCategoryCategory265Privilege / Sandbox Issues
Development Concepts (primary)699
ParentOfCategoryCategory275Permission Issues
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class282Improper Ownership Management
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class284Access Control (Authorization) Issues
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class286Incorrect User Management
Development Concepts (primary)699
MemberOfViewView635Weaknesses Used by NVD
Weaknesses Used by NVD (primary)635
CanAlsoBeWeakness BaseWeakness Base283Unverified Ownership
Research Concepts1000
+ Taxonomy Mappings
PLOVERPermissions, Privileges, and ACLs
+ Related Attack Patterns
5Analog In-band Switching Signals (aka Blue Boxing)
17Accessing, Modifying or Executing Executable Files
35Leverage Executable Code in Nonexecutable Files
58Restful Privilege Elevation
69Target Programs with Elevated Privileges
76Manipulating Input to File System Calls
[REF-11] M. Howard and D. LeBlanc. "Writing Secure Code". Chapter 7, "How Tokens, Privileges, SIDs, ACLs, and Processes Relate" Page 218. 2nd Edition. Microsoft. 2002.
