CWE-1220— Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1220page 1 of 3
- CVE-2025-31201CRITICALCVSS 9.8EG 9.8⚠ KEV2025-04-16
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Po…
- CVE-2026-56155CRITICALCVSS 7.8EG 9.0⚠ KEV2026-07-14
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-33825CRITICALCVSS 7.8EG 9.0⚠ KEV2026-04-14
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2022-2475CRITICALCVSS 9.8EG 9.82022-10-28
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could all…
- CVE-2026-6356CRITICALCVSS 9.6EG 9.62026-04-22
A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information.
- CVE-2026-6388CRITICALCVSS 9.1EG 9.12026-04-15
A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient valida…
- CVE-2025-8053CRITICALCVSS 9.1EG 9.12025-10-20
Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low privilege user to interact with the backend API with…
- CVE-2025-7493CRITICALCVSS 9.1EG 9.12025-09-30
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version ad…
- CVE-2025-4404CRITICALCVSS 9.1EG 9.12025-06-17
A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services w…
- CVE-2026-2651CRITICALCVSS 9.0EG 9.02026-05-25
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/m…
- CVE-2026-77480HIGHCVSS 8.8EG 8.82026-09-08
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-66814HIGHCVSS 8.8EG 8.82026-09-08
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50502HIGHCVSS 8.8EG 8.82026-07-14
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- CVE-2026-40365HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-35436HIGHCVSS 8.8EG 8.82026-05-12
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2025-8049HIGHCVSS 8.8EG 8.82025-10-20
Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low-privilege user to elevate privileges within the appl…
- CVE-2025-29987HIGHCVSS 8.8EG 8.82025-04-03
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this v…
- CVE-2023-45217HIGHCVSS 8.8EG 8.82024-05-16
Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-40070HIGHCVSS 8.8EG 8.82024-05-16
Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36110HIGHCVSS 8.8EG 8.82022-09-09
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, t…
- CVE-2024-21962HIGHCVSS 8.6EG 8.62026-05-15
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution.
- CVE-2026-41326HIGHCVSS 8.2EG 8.22026-04-24
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handl…
- CVE-2025-3648HIGHCVSS 8.2EG 8.22025-07-08
A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and…
- CVE-2024-52799HIGHCVSS 8.2EG 8.22024-11-21
Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the worst being create pods/exec, which will allow kubectl exec into any Pod in the s…
- CVE-2024-5389HIGHCVSS 8.1EG 8.12024-06-09
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the ap…
- CVE-2023-33127HIGHCVSS 8.1EG 8.12023-07-11
.NET and Visual Studio Elevation of Privilege Vulnerability
- CVE-2025-35998HIGHCVSS 7.9EG 7.92026-02-10
Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user …
- CVE-2026-62721HIGHCVSS 7.8EG 7.82026-08-11
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-50405HIGHCVSS 7.8EG 7.82026-07-14
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-48581HIGHCVSS 7.8EG 7.82026-07-14
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
- CVE-2026-55006HIGHCVSS 7.8EG 7.82026-07-14
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-49170HIGHCVSS 7.8EG 7.82026-07-14
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- CVE-2024-53295HIGHCVSS 7.8EG 7.82025-02-01
Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of pri…
- CVE-2023-44285HIGHCVSS 7.8EG 7.82023-12-14
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to…
- CVE-2026-40981HIGHCVSS 7.5EG 7.52026-05-07
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 t…
- CVE-2026-39363HIGHCVSS 7.5EG 7.52026-04-07
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…
- CVE-2024-21947HIGHCVSS 7.5EG 7.52025-09-06
Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at the SMM level.
- CVE-2025-22839HIGHCVSS 7.5EG 7.52025-08-12
Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
- CVE-2024-33058HIGHCVSS 7.5EG 7.52025-04-07
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
- CVE-2023-31343HIGHCVSS 7.5EG 7.52025-02-11
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
- CVE-2023-31342HIGHCVSS 7.5EG 7.52025-02-11
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
- CVE-2024-13256HIGHCVSS 7.5EG 7.52025-01-09
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.
- CVE-2024-8927HIGHCVSS 7.5EG 7.52024-10-08
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this va…
- CVE-2023-27591HIGHCVSS 7.5EG 7.52023-03-17
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETW…
- CVE-2024-4147HIGHCVSS 6.5EG 7.52026-02-02
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete prompts created in other organizations through ID manipulation. The vulnerability stems from the application's failure t…
- CVE-2026-78122HIGHCVSS 7.4EG 7.42026-08-22
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /contai…
- CVE-2025-20111HIGHCVSS 7.4EG 7.42025-02-26
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpect…
- CVE-2024-42365HIGHCVSS 7.4EG 7.42024-08-08
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may chang…
- CVE-2026-15431HIGHCVSS 7.3EG 7.32026-09-03
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient acces…
- CVE-2021-31384HIGHCVSS 7.2EG 7.22021-10-19
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web a…
Map vulnerabilities like CWE-1220 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1220 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →