CWE-1220
Insufficient Granularity of Access Control
Description
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180
CVEs mapped to this weakness (106)
page 6 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49170 | Hig | 0.00 | 7.8 | 0.03 | Jul 14, 2026 | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-48581 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | ||
| CVE-2023-50713 | Med | 0.00 | 6.5 | 0.00 | Dec 14, 2023 | Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a… | ||
| CVE-2023-3227 | Med | 0.00 | 5.7 | 0.00 | Jun 14, 2023 | Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2022-1461 | Med | 0.00 | 6.5 | 0.01 | Apr 25, 2022 | Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1177 | Med | 0.00 | 4.3 | 0.01 | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. |
- risk 0.00cvss 7.8epss 0.03
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.5epss 0.00
Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a…
- risk 0.00cvss 5.7epss 0.00
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 6.5epss 0.01
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 4.3epss 0.01
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.