CWE-1220
99 CVEs • Abstraction: Base
Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
CVEs (99)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreJul 15, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. |
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. |
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. |
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's s...Show more |
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administr...Show more |
Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential es...Show more |
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permis...Show more |
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate...Show more |
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege es...Show more |
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution. |
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 May 12, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: af...Show more |
1Katacontainers 2Confidential Containers Kata ContainersJul 15, 2026 Apr 24, 2026 8.2 HIGH· v4 8.2 HIGH· v3 N/A· v2 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps...Show more |
The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existen...Show more |
The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL...Show more |
A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information. |