CWE-1220— Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.— MITRE CWE catalog
115 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1220page 3 of 3
- CVE-2026-50502HIGHCVSS 8.8EG 8.82026-07-14
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- CVE-2026-55006HIGHCVSS 7.8EG 7.82026-07-14
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-56155CRITICALCVSS 7.8EG 9.0⚠ KEV2026-07-14
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-62721HIGHCVSS 7.8EG 7.82026-08-11
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-6356CRITICALCVSS 9.6EG 9.62026-04-22
A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information.
- CVE-2026-6388CRITICALCVSS 9.1EG 9.12026-04-15
A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient valida…
- CVE-2026-66814HIGHCVSS 8.8EG 8.82026-09-08
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68868MEDIUMCVSS 6.5EG 6.52026-08-12
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal cal…
- CVE-2026-69267MEDIUMCVSS 6.5EG 6.52026-09-08
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.
- CVE-2026-77480HIGHCVSS 8.8EG 8.82026-09-08
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-78122HIGHCVSS 7.4EG 7.42026-08-22
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /contai…
- CVE-2026-78216MEDIUMCVSS 6.0EG 6.02026-09-08
AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash fiel…
- CVE-2026-78230MEDIUMCVSS 6.0EG 6.02026-09-08
AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies re…
- CVE-2026-86338MEDIUMCVSS 6.0EG 6.02026-09-16
Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as …
- CVE-2026-9088LOWCVSS 2.7EG 2.72026-06-05
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user a…
Map vulnerabilities like CWE-1220 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1220 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →