CWE•Base•Incomplete•12 recent CVEs
CWE-1220Insufficient Granularity of Access Control
Description
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
[object Object]
Common consequences
- Confidentiality,Integrity,Availability,Access Control→Modify Memory,Read Memory,Execute Unauthorized Code or Commands,Gain Privileges or Assume Identity,Bypass Protection Mec
Potential mitigations
- Architecture and Design,Implementation,Testing[object Object]
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-90882.72026-06-05CVE-2021-467472026-06-01CVE-2026-379814.32026-05-19CVE-2024-219622026-05-15CVE-2026-403658.82026-05-12CVE-2026-354368.82026-05-12CVE-2026-406904.32026-04-24CVE-2026-387434.32026-04-24CVE-2026-63569.62026-04-22CVE-2026-338257.82026-04-14CVE-2025-206282026-04-07CVE-2022-361108.82022-09-09