Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-1220

Insufficient Granularity of Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

100
Assigned CVEs
175th
Commonality Rank
6.8
Avg CVSS
3.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-1220 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2021
4 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

100 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-56155HIGH
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Jul 14, 20267.879YESNO
CVE-2026-33825HIGH
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Apr 14, 20267.877YESNO
CVE-2025-31201CRITICAL
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with a
Apr 16, 20259.877YESNO
CVE-2026-39363HIGH
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin
Apr 7, 20267.542NOYES
CVE-2026-50502HIGH
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
Jul 14, 20268.837NONO
CVE-2024-42365HIGH
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 a
Aug 8, 20248.837NOYES
CVE-2026-2651CRITICAL
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logi
May 25, 20269.036NONO
CVE-2026-49170HIGH
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Jul 14, 20267.835NONO
CVE-2026-41326HIGH
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an overs
Apr 24, 20268.234NONO
CVE-2026-6388CRITICAL
A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to byp
Apr 15, 20269.134NONO
View all 100 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
16%
10%
4.0-4.9
14%
19%
5.0-5.9
11%
16%
6.0-6.9
29%
26%
7.0-7.9
16%
11%
8.0-8.9
9%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
3 CVEs
3.0% of CVEs· 97th percentile
Metasploit
1 CVE
1.0% of CVEs· 87th percentile
Nuclei
1 CVE
1.0% of CVEs· 85th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products