Incorrect User Management
CWE-286 · Class · Incomplete
The product does not properly manage a user within its environment.
Extended description
Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.