The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Volume of CVEs assigned to CWE-1220 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
100 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56155HIGH Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 79 | YES | NO |
CVE-2026-33825HIGH Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | Apr 14, 2026 | 7.8 | 77 | YES | NO |
CVE-2025-31201CRITICAL This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with a | Apr 16, 2025 | 9.8 | 77 | YES | NO |
CVE-2026-39363HIGH Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-50502HIGH Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. | Jul 14, 2026 | 8.8 | 37 | NO | NO |
CVE-2024-42365HIGH Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 a | Aug 8, 2024 | 8.8 | 37 | NO | YES |
CVE-2026-2651CRITICAL A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logi | May 25, 2026 | 9.0 | 36 | NO | NO |
CVE-2026-49170HIGH Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 35 | NO | NO |
CVE-2026-41326HIGH Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an overs | Apr 24, 2026 | 8.2 | 34 | NO | NO |
CVE-2026-6388CRITICAL A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to byp | Apr 15, 2026 | 9.1 | 34 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.