VYPR

CWE-1220

Insufficient Granularity of Access Control

BaseIncomplete

Description

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180

CVEs mapped to this weakness (106)

page 5 of 6
  • CVE-2022-4801MedDec 28, 2022
    risk 0.28cvss 5.3epss 0.01

    Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-48514MedFeb 10, 2026
    risk 0.26cvss epss 0.00

    Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.

  • CVE-2024-26246LowMar 14, 2024
    risk 0.25cvss 3.9epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2025-31961LowAug 15, 2025
    risk 0.24cvss 3.7epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

  • CVE-2025-5982LowJun 12, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

  • CVE-2026-37981MedMay 19, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for…

  • CVE-2026-40690MedApr 24, 2026
    risk 0.21cvss 4.3epss 0.00

    The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized…

  • CVE-2026-38743MedApr 24, 2026
    risk 0.21cvss 4.3epss 0.00

    The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full…

  • CVE-2022-4813MedDec 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-2498LowAug 13, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

  • CVE-2023-39418LowAug 11, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

  • CVE-2025-1110LowMay 22, 2025
    risk 0.18cvss 2.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

  • CVE-2024-39324LowJul 2, 2024
    risk 0.18cvss 3.8epss 0.00

    aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end.…

  • CVE-2026-56155HigKEVJul 14, 2026
    risk 0.12cvss 7.8epss 0.02

    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-9088LowJun 5, 2026
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…

  • CVE-2024-52814LowNov 22, 2024
    risk 0.11cvss 2.8epss 0.00

    Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only…

  • CVE-2024-42365HigAug 8, 2024
    risk 0.03cvss 7.4epss 0.05

    Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the…

  • CVE-2026-50502HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

  • CVE-2026-50405HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55006HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.