CWE-1220
Insufficient Granularity of Access Control
Description
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180
CVEs mapped to this weakness (118)
page 6 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4813 | Med | 0.21 | 4.3 | 0.01 | Dec 28, 2022 | Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2025-2498 | Low | 0.20 | 3.1 | 0.00 | Aug 13, 2025 | An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions. | ||
| CVE-2023-39418 | Low | 0.20 | 3.1 | 0.01 | Aug 11, 2023 | A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows. | ||
| CVE-2025-1110 | Low | 0.18 | 2.7 | 0.00 | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query. | ||
| CVE-2024-39324 | Low | 0.18 | 3.8 | 0.00 | Jul 2, 2024 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end.… | ||
| CVE-2026-56155 | Hig | 0.12 | 7.8 | 0.00 | KEV | Jul 14, 2026 | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-9088 | Low | 0.11 | 2.7 | 0.00 | Jun 5, 2026 | A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured… | ||
| CVE-2024-52814 | Low | 0.11 | 2.8 | 0.00 | Nov 22, 2024 | Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only… | ||
| CVE-2024-42365 | Hig | 0.03 | 7.4 | 0.05 | Aug 8, 2024 | Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the… | ||
| CVE-2026-50502 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. | ||
| CVE-2026-50405 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55006 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49170 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-48581 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | ||
| CVE-2023-50713 | Med | 0.00 | 6.5 | 0.00 | Dec 14, 2023 | Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a… | ||
| CVE-2023-3227 | Med | 0.00 | 5.7 | 0.00 | Jun 14, 2023 | Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2022-1461 | Med | 0.00 | 6.5 | 0.01 | Apr 25, 2022 | Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1177 | Med | 0.00 | 4.3 | 0.01 | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. |
- risk 0.21cvss 4.3epss 0.01
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.20cvss 3.1epss 0.00
An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.
- risk 0.20cvss 3.1epss 0.01
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
- risk 0.18cvss 2.7epss 0.00
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.
- risk 0.18cvss 3.8epss 0.00
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end.…
- risk 0.12cvss 7.8epss 0.00
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- risk 0.11cvss 2.7epss 0.00
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…
- risk 0.11cvss 2.8epss 0.00
Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only…
- risk 0.03cvss 7.4epss 0.05
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the…
- risk 0.00cvss 8.0epss 0.01
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- risk 0.00cvss 7.8epss 0.00
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.5epss 0.00
Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a…
- risk 0.00cvss 5.7epss 0.00
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 6.5epss 0.01
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 4.3epss 0.01
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.