VYPR

CWE-1220

Insufficient Granularity of Access Control

BaseIncomplete

Description

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180

CVEs mapped to this weakness (118)

page 6 of 6
  • CVE-2022-4813MedDec 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-2498LowAug 13, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

  • CVE-2023-39418LowAug 11, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

  • CVE-2025-1110LowMay 22, 2025
    risk 0.18cvss 2.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.

  • CVE-2024-39324LowJul 2, 2024
    risk 0.18cvss 3.8epss 0.00

    aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end.…

  • CVE-2026-56155HigKEVJul 14, 2026
    risk 0.12cvss 7.8epss 0.00

    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-9088LowJun 5, 2026
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…

  • CVE-2024-52814LowNov 22, 2024
    risk 0.11cvss 2.8epss 0.00

    Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions to `workflowtasksets` and `workflowartifactgctasks` to all workflow Pods, when only…

  • CVE-2024-42365HigAug 8, 2024
    risk 0.03cvss 7.4epss 0.05

    Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the…

  • CVE-2026-50502HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

  • CVE-2026-50405HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55006HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49170HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48581HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

  • CVE-2023-50713MedDec 14, 2023
    risk 0.00cvss 6.5epss 0.00

    Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a…

  • CVE-2023-3227MedJun 14, 2023
    risk 0.00cvss 5.7epss 0.00

    Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.

  • CVE-2022-1461MedApr 25, 2022
    risk 0.00cvss 6.5epss 0.01

    Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-1177MedMar 30, 2022
    risk 0.00cvss 4.3epss 0.01

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.