BaseIncomplete
CWE-1220Insufficient Granularity of Access Control
Category: other
Description
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Common consequences· 1
- Confidentiality / Integrity / Availability / Access Control — Modify Memory, Read Memory, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, Bypass Protection Mechanism, Other
Potential mitigations· 1
- [Architecture and Design, Implementation, Testing]
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Accessing Functionality Not Properly Constrained by ACLscapec-1 | 100% | live |
| AttackPattern | Exploiting Incorrectly Configured Access Control Security Levelscapec-180 | 100% | live |
(incoming)13
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-29987cve-2025-29987 | 0% | live |
| Vulnerability | Apple Multiple Products Arbitrary Read and Write Vulnerabilitycve-2025-31201 | 0% | live |
| Vulnerability | CVE-2025-4404cve-2025-4404 | 0% | live |
| Vulnerability | CVE-2025-7493cve-2025-7493 | 0% | live |
| Vulnerability | CVE-2025-8049cve-2025-8049 | 0% | live |
| Vulnerability | CVE-2025-8053cve-2025-8053 | 0% | live |
| Vulnerability | Microsoft Defender Insufficient Granularity of Access Control Vulnerabilitycve-2026-33825 | 0% | live |
| Vulnerability | CVE-2026-35436cve-2026-35436 | 0% | live |
| Vulnerability | CVE-2026-40365cve-2026-40365 | 0% | live |
| Vulnerability | CVE-2026-6356cve-2026-6356 | 0% | live |
| Vulnerability | CVE-2026-6388cve-2026-6388 | 0% | live |
| KEVEntry | Microsoft Windows SAM Local Privilege Escalation Vulnerabilitykev-cve-2021-36934 | 0% | live |
| KEVEntry | Microsoft Defender Insufficient Granularity of Access Control Vulnerabilitykev-cve-2026-33825 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.