CWE-1220: Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
102 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-7493 — Freeipa: idm: privilege escalation from host to domain admin in freeipa
- CVE-2025-29987 — Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficie
- CVE-2024-52799 — Argo Workflows Chart: Excessive Privileges in Workflow Role
- CVE-2025-3648 — Data Inference in Now Platform via Conditional ACLs
- CVE-2024-53295 — Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerabilit
- CVE-2025-4404 — Freeipa: idm: privilege escalation from host to domain admin in freeipa
- CVE-2026-6388 — Argocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient namespace validation
- CVE-2025-22839 — Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a pr
- CVE-2024-4147 — Insufficient Access Control in lunary-ai/lunary
- CVE-2024-33058 — Insufficient Granularity of Access Control in Core
- CVE-2025-20111 — Cisco Nexus 3000 and 9000 Series Switches Layer 2 Ethernet Denial of Service Vulnerability
- CVE-2024-42365 — Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
- CVE-2024-21962 — Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent
- CVE-2024-39323 — aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
- CVE-2026-78122 — docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
- CVE-2025-54461 — ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited
- CVE-2024-39279 — Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user t
- CVE-2024-29200 — API returns timesheet entries a user should not be authorized to view
- CVE-2026-15431 — HP Support Assistant – Potential Escalation of Privilege
- CVE-2026-40145 — Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility
Recently published
- CVE-2026-78216 — AshLua eval read operations can read field-policy-protected fields via aggregates
- CVE-2026-78230 — AshAi aggregate tool can read field-policy-protected fields
- CVE-2026-15431 — HP Support Assistant – Potential Escalation of Privilege
- CVE-2026-78122 — docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
- CVE-2026-40145 — Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility
- CVE-2026-68868 — Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
- CVE-2025-31938 — Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(
- CVE-2026-16560 — 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn
- CVE-2026-16106 — Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles
- CVE-2026-16108 — Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2
- CVE-2026-14615 — Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter
- CVE-2026-14613 — Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission
- CVE-2026-9088 — Keycloak: keycloak: information disclosure due to user profile permission bypass
- CVE-2021-46747 — Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user sp
- CVE-2026-37981 — Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access control in user lookup endpoint
- CVE-2024-21962 — Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent
- CVE-2026-38743 — Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities
- CVE-2026-40690 — Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users
- CVE-2026-6388 — Argocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient namespace validation
- CVE-2025-20628 — Insufficient granularity of access control for Remote Connector Servers in client mode
More specific weaknesses
- CWE-1222 — Insufficient Granularity of Address Regions Protected by Register Locks