CWE-1220

Insufficient Granularity of Access Control

Parent: CWE-284 - Improper Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

100 vulnerabilities with CWE-1220
CVE-2026-16560 MEDIUM
389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn
CVSS 5.3
CVE-2026-50502 HIGH
Microsoft Windows 10 Version 1607 - Windows Event Logging Service Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-50405 HIGH
Microsoft Windows 10 Version 1607 - Windows Filtering Platform Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-56155 HIGH KEV
Microsoft Windows 10 Version 1607 - Active Directory Federation Services Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-55006 HIGH
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-49170 HIGH
Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-48581 HIGH
Microsoft Surface Go - Surface Broker SDMA Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-14615 MEDIUM
Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter
CVSS 4.3
CVE-2026-9088 LOW
Keycloak: keycloak: information disclosure due to user profile permission bypass
CVSS 2.7
CVE-2026-2651 CRITICAL
Missing Authorization Validation in mlflow/mlflow
CVSS 9.0
CVE-2026-37981 MEDIUM
Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint
CVSS 4.3
CVE-2026-40365 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-35436 HIGH
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-40981 HIGH
Spring Cloud Config Authorization Bypass via Google Secrets Manager
CVSS 7.5
CVE-2026-41326 HIGH
Kata Containers: CopyFile Policy Subversion via Symlinks
CVSS 8.2
CVE-2026-40690 MEDIUM
Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users
CVSS 4.3
CVE-2026-38743 MEDIUM
Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities
CVSS 4.3
CVE-2026-6356 CRITICAL
Augmentt 1.0 - Privilege Escalation
CVSS 9.6
CVE-2026-6388 CRITICAL
Argocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient namespace validation
CVSS 9.1
CVE-2026-33825 HIGH KEV
Microsoft Defender Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-39363 HIGH
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
CVSS 7.5
CVE-2026-20107 MEDIUM
Cisco APIC 6.1(1f-3g) Authenticated DoS via Crafted CLI Commands
CVSS 5.5
CVE-2026-0873 MEDIUM
Ercom Cryptobox >=v4.40.x - Authenticated Privilege Escalation to Global Administrator
CVE-2025-54518 HIGH
Amd Epyc™ 7002 Series Processors - Improper Isolation of Shared Resources on System-on-a-Chip (SoC)
CVSS 7.0
CVE-2025-20628 MEDIUM
Insufficient granularity of access control for Remote Connector Servers in client mode
Details
Vulnerabilities 100