CWE-1220— Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1220page 3 of 3
- CVE-2025-20305MEDIUMCVSS 4.3EG 4.32025-11-05
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data p…
- CVE-2022-4813MEDIUMCVSS 4.3EG 4.32022-12-28
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-1177MEDIUMCVSS 4.3EG 4.32022-03-30
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
- CVE-2026-14615MEDIUMCVSS 2.7EG 4.32026-07-03
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions…
- CVE-2025-7001MEDIUMCVSS 2.7EG 4.32025-07-24
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API …
- CVE-2025-48514MEDIUMCVSS 4.0EG 4.02026-02-10
Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.
- CVE-2024-26246LOWCVSS 3.9EG 3.92024-03-14
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- CVE-2024-39324LOWCVSS 3.8EG 3.82024-07-02
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API whi…
- CVE-2025-31961LOWCVSS 3.7EG 3.72025-08-15
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
- CVE-2025-5982LOWCVSS 3.7EG 3.72025-06-12
An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
- CVE-2025-2498LOWCVSS 3.1EG 3.12025-08-13
An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups …
- CVE-2023-39418LOWCVSS 3.1EG 3.12023-08-11
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not…
- CVE-2024-52814LOWCVSS 2.8EG 2.82024-11-22
Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgc…
- CVE-2026-9088LOWCVSS 2.7EG 2.72026-06-05
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user a…
- CVE-2025-1110LOWCVSS 2.7EG 2.72025-05-22
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.
Map vulnerabilities like CWE-1220 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1220 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →