CWE•Base•Incomplete•20 recent CVEs
CWE-1220Insufficient Granularity of Access Control
Description
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
[object Object]
Common consequences
- Confidentiality,Integrity,Availability,Access Control→Modify Memory,Read Memory,Execute Unauthorized Code or Commands,Gain Privileges or Assume Identity,Bypass Protection Mec
Potential mitigations
- Architecture and Design,Implementation,Testing[object Object]
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-774808.82026-09-08CVE-2026-692676.52026-09-08CVE-2026-668148.82026-09-08CVE-2026-782302026-09-08CVE-2026-782162026-09-08CVE-2026-154312026-09-03CVE-2026-781227.42026-08-22CVE-2026-401452026-08-17CVE-2026-688686.52026-08-12CVE-2026-627217.82026-08-11CVE-2025-319382026-08-11CVE-2026-165605.32026-07-22CVE-2026-161084.32026-07-17CVE-2026-161064.92026-07-17CVE-2026-505028.02026-07-14CVE-2026-504057.82026-07-14CVE-2026-561557.82026-07-14CVE-2026-550067.82026-07-14CVE-2026-491707.82026-07-14CVE-2026-485817.82026-07-14