← Back
CWE-1220

108 CVEs • Abstraction: Base

Insufficient Granularity of Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

JSON object

Loading...

CVEs (108)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Miniflux Project
1Miniflux
Jun 17, 2026
Mar 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `M...Show more
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the default). A patch is available in Miniflux 2.0.43. As a workaround, set `METRICS_COLLECTOR` to `false` (default) or run Miniflux behind a trusted reverse-proxy.Show less
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
1Haascnc
1Haas Controller Firmware
Jun 17, 2026
Oct 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible ra...Show more
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context.Show less
2Gravitl
Netmaker
2Netmaker
Netmaker
Jun 17, 2026
Sep 9, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have...Show more
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, they can use their auth tokens to run admin-level functions via the API. This problem has been patched in v0.15.1.Show less
1Open Emr
1Openemr
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
1Open Emr
1Openemr
Jun 17, 2026
Mar 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
1Juniper
1Junos
Jun 17, 2026
Oct 19, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempt...Show more
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.Show less