CWE-282: Improper Ownership Management
The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.
Last updated
Overview
CWE-282 (Improper Ownership Management) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
26 recorded CVEs are caused by CWE-282 (Improper Ownership Management), including 1 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 3 new CWE-282 CVEs have been recorded so far in 2026 (10 in 2025).