VYPR

CWE-1220

Insufficient Granularity of Access Control

BaseIncomplete

Description

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180

CVEs mapped to this weakness (106)

page 1 of 6
  • CVE-2025-31201CriKEVApr 16, 2025
    risk 0.77cvss 9.8epss 0.15

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of…

  • CVE-2026-33825HigKEVApr 14, 2026
    risk 0.69cvss 7.8epss 0.07

    Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

  • CVE-2022-2475CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources…

  • CVE-2026-6356CriApr 22, 2026
    risk 0.62cvss 9.6epss 0.00

    A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information.

  • CVE-2026-6388CriApr 15, 2026
    risk 0.59cvss 9.1epss 0.00

    A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger…

  • CVE-2025-8053CriOct 20, 2025
    risk 0.59cvss 9.1epss 0.00

    Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low privilege user to interact with the backend API without sufficient privileges. This issue…

  • CVE-2025-7493CriSep 30, 2025
    risk 0.59cvss 9.1epss 0.01

    A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM…

  • CVE-2025-4404CriJun 17, 2025
    risk 0.59cvss 9.1epss 0.02

    A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM…

  • CVE-2026-40365HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-35436HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

  • CVE-2025-8049HigOct 20, 2025
    risk 0.57cvss 8.8epss 0.00

    Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low-privilege user to elevate privileges within the application. This issue affects Flipper:…

  • CVE-2025-29987HigApr 3, 2025
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary…

  • CVE-2023-45217HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40070HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-21962HigMay 15, 2026
    risk 0.56cvss epss 0.00

    Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution.

  • CVE-2025-3648HigJul 8, 2025
    risk 0.53cvss epss 0.02

    A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query…

  • CVE-2023-33127HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.02

    .NET and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2026-2651CriMay 25, 2026
    risk 0.52cvss 9.0epss 0.00

    A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints,…

  • CVE-2026-62721HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-35998HigFeb 10, 2026
    risk 0.51cvss 7.9epss 0.00

    Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack…