CWE-1220

Insufficient Granularity of Access Control

Parent: CWE-284 - Improper Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

73 vulnerabilities with CWE-1220
CVE-2026-20107 MEDIUM
Cisco APIC - DoS
CVSS 5.5
CVE-2025-48517
SEV firmware - Privilege Escalation
CVE-2025-48514
SEV firmware - Privilege Escalation
CVE-2026-0873
Cryptobox - Privilege Escalation
CVE-2024-4147 MEDIUM
lunary-ai/lunary <1.2.13 - Privilege Escalation
CVSS 6.5
CVE-2025-11246 MEDIUM
GitLab CE/EE <18.5.5-18.7.1 - Privilege Escalation
CVSS 5.4
CVE-2025-8306
Asseco InfoMedica - Info Disclosure
CVE-2025-20305 MEDIUM
Cisco ISE - Info Disclosure
CVSS 4.3
CVE-2025-8053 CRITICAL
Opentext Flipper <3.1.2 - Privilege Escalation
CVSS 9.1
CVE-2025-8049 HIGH
Opentext Flipper <3.1.2 - Privilege Escalation
CVSS 8.8
CVE-2025-54461 MEDIUM
ChatLuck - Info Disclosure
CVSS 5.3
CVE-2025-7493 CRITICAL
FreeIPA - Privilege Escalation
CVSS 9.1
CVE-2024-21947 HIGH
System Management Mode - Memory Corruption
CVSS 7.5
CVE-2025-31961 LOW
HCL Connections - Info Disclosure
CVSS 3.7
CVE-2025-2498 LOW
Gitlab EE <18.0.6-18.2.2 - Auth Bypass
CVSS 3.1
CVE-2025-22839 HIGH
Intel(R) Xeon(R) 6 Scalable - Privilege Escalation
CVSS 7.5
CVE-2025-7001 MEDIUM
GitLab CE/EE <18.0.5-18.2.1 - Privilege Escalation
CVSS 4.3
CVE-2025-3648
ServiceNow - Info Disclosure
CVE-2025-27026 MEDIUM
Infinera G42 R6.1.3 - Privilege Escalation
CVSS 4.9
CVE-2025-4404 CRITICAL
FreeIPA - Privilege Escalation
CVSS 9.1
CVE-2025-5982 LOW
GitLab EE <17.10.8-18.0.2 - Auth Bypass
CVSS 3.7
CVE-2025-4979 MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Info Disclosure
CVSS 4.9
CVE-2025-1110 LOW
Gitlab - Incorrect Authorization
CVSS 2.7
CVE-2025-32703 MEDIUM
Microsoft Visual Studio 2017 < 15.9.73 - Information Disclosure
CVSS 5.5
CVE-2025-1278 MEDIUM
GitLab CE/EE <17.9.8-17.11.2 - Auth Bypass
CVSS 5.3
Details
Vulnerabilities 73