CWE-1220— Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1220page 2 of 3
- CVE-2026-40145HIGHCVSS 7.1EG 7.12026-08-17
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process…
- CVE-2021-46747HIGHCVSS 7.1EG 7.12026-06-01
Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privile…
- CVE-2024-39323HIGHCVSS 7.1EG 7.12024-07-02
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over…
- CVE-2025-54518HIGHCVSS 7.0EG 7.02026-05-15
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
- CVE-2025-20628MEDIUMCVSS 6.9EG 6.92026-04-07
An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. T…
- CVE-2024-29200MEDIUMCVSS 6.8EG 6.82024-03-28
Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` per…
- CVE-2023-6725MEDIUMCVSS 5.5EG 6.62024-03-15
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploi…
- CVE-2026-69267MEDIUMCVSS 6.5EG 6.52026-09-08
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.
- CVE-2026-68868MEDIUMCVSS 6.5EG 6.52026-08-12
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal cal…
- CVE-2026-16108MEDIUMCVSS 6.5EG 6.52026-07-17
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administ…
- CVE-2025-69196MEDIUMCVSS 6.5EG 6.52026-03-16
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the to…
- CVE-2024-39279MEDIUMCVSS 6.5EG 6.52025-02-12
Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.
- CVE-2024-6867MEDIUMCVSS 6.5EG 6.52024-09-13
An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As …
- CVE-2023-43040MEDIUMCVSS 6.5EG 6.52024-05-14
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
- CVE-2023-32259MEDIUMCVSS 6.5EG 6.52024-03-19
Insufficient Granularity of Access Control vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
- CVE-2023-4456MEDIUMCVSS 6.5EG 6.52023-08-21
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the …
- CVE-2022-1461MEDIUMCVSS 6.5EG 6.52022-04-25
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- CVE-2024-11931MEDIUMCVSS 6.4EG 6.42025-01-24
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer …
- CVE-2024-13272MEDIUMCVSS 6.3EG 6.32025-01-09
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.
- CVE-2026-86338MEDIUMCVSS 6.0EG 6.02026-09-16
Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as …
- CVE-2026-78216MEDIUMCVSS 6.0EG 6.02026-09-08
AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash fiel…
- CVE-2026-78230MEDIUMCVSS 6.0EG 6.02026-09-08
AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies re…
- CVE-2024-43604MEDIUMCVSS 5.7EG 5.72024-10-08
Outlook for Android Elevation of Privilege Vulnerability
- CVE-2023-3227MEDIUMCVSS 5.7EG 5.72023-06-14
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- CVE-2026-20107MEDIUMCVSS 5.5EG 5.52026-02-25
A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of servic…
- CVE-2025-32703MEDIUMCVSS 5.5EG 5.52025-05-13
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
- CVE-2024-21971MEDIUMCVSS 5.5EG 5.52025-02-12
Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an operating system crash, potentially leading to denial of service.
- CVE-2025-11246MEDIUMCVSS 5.4EG 5.42026-01-09
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners…
- CVE-2026-16560MEDIUMCVSS 5.3EG 5.32026-07-22
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of ser…
- CVE-2025-54461MEDIUMCVSS 5.3EG 5.32025-10-16
ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a guest user.
- CVE-2025-1278MEDIUMCVSS 5.3EG 5.32025-05-09
An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
- CVE-2025-2408MEDIUMCVSS 5.3EG 5.32025-04-10
An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions users could bypass IP access restrictions and view sensitive information.
- CVE-2024-2412MEDIUMCVSS 5.3EG 5.32024-03-13
The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
- CVE-2022-4801MEDIUMCVSS 5.3EG 5.32022-12-28
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2024-12619MEDIUMCVSS 5.2EG 5.22025-03-28
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.
- CVE-2025-8306MEDIUMCVSS 5.1EG 5.12026-01-08
Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due…
- CVE-2023-50713MEDIUMCVSS 5.0EG 5.02023-12-14
Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' …
- CVE-2023-0205MEDIUMCVSS 5.0EG 5.02023-04-22
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.
- CVE-2023-0203MEDIUMCVSS 5.0EG 5.02023-04-22
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.
- CVE-2026-16106MEDIUMCVSS 4.9EG 4.92026-07-17
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, …
- CVE-2026-14613MEDIUMCVSS 4.9EG 4.92026-07-03
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an…
- CVE-2025-27026MEDIUMCVSS 4.9EG 4.92025-07-02
A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation…
- CVE-2025-4979MEDIUMCVSS 4.9EG 4.92025-05-22
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by s…
- CVE-2024-6696MEDIUMCVSS 4.9EG 4.92025-02-20
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required g…
- CVE-2026-0873MEDIUMCVSS 4.8EG 4.82026-02-04
On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptobox administration console allows an authenticated entity administrator with knowledge to elevate his account to global …
- CVE-2025-48517MEDIUMCVSS 4.6EG 4.62026-02-10
Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of con…
- CVE-2025-31938MEDIUMCVSS 4.3EG 4.32026-08-11
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high comple…
- CVE-2026-37981MEDIUMCVSS 4.3EG 4.32026-05-19
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest person…
- CVE-2026-40690MEDIUMCVSS 4.3EG 4.32026-04-24
The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAG…
- CVE-2026-38743MEDIUMCVSS 4.3EG 4.32026-04-24
The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including…
Map vulnerabilities like CWE-1220 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1220 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →