VYPR

CWE-1220

Insufficient Granularity of Access Control

BaseIncomplete

Description

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180

CVEs mapped to this weakness (106)

page 6 of 6
  • CVE-2026-49170HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48581HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

  • CVE-2023-50713MedDec 14, 2023
    risk 0.00cvss 6.5epss 0.00

    Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a…

  • CVE-2023-3227MedJun 14, 2023
    risk 0.00cvss 5.7epss 0.00

    Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.

  • CVE-2022-1461MedApr 25, 2022
    risk 0.00cvss 6.5epss 0.01

    Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-1177MedMar 30, 2022
    risk 0.00cvss 4.3epss 0.01

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.