CWE-1220Base2 in KEV

Insufficient Granularity of Access Control

Incomplete in the CWE catalog · 100 CVEs mapped

100
CVEs mapped
2
In KEV
6.5
Median CVSS
What it is

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Recent examples
none
CVE-2026-15431

CVE-2026-15431 - UNKNOWN Severity Vulnerability

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

no explanation yet
0%
epss
7.4cvss
CVE-2026-78122

CVE-2026-78122 - HIGH Severity Vulnerability

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

HIGHno explanation yet
0%
epss
none
CVE-2026-40145

CVE-2026-40145 - UNKNOWN Severity Vulnerability

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1220
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)