CWE-286: Incorrect User Management
The product does not properly manage a user within its environment.
Overview
Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.
Real-world CVEs
29 recorded CVEs are caused by CWE-286 (Incorrect User Management). The highest-severity and most recent are shown first. 1 new CWE-286 CVE has been recorded so far in 2026 (9 in 2025).