Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-1220

MITRE ↗

CWE-1220

3
CRITICAL
16
HIGH
10
MEDIUM
1
LOW
39 CVEs
9.6
CVE-2026-6356

A vulnerability in the web application allows standard users to escalate their privileges to those of a super administra

9.1
CVE-2026-6388

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an

9.0
CVE-2026-2651

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the

8.8
CVE-2026-35436

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-40365

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.2
CVE-2026-41326

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th

8.0
CVE-2026-50502

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute cod

7.9
CVE-2025-35998

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R)

7.8
CVE-2026-33825 KEV

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges loc

7.8
CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-49170

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi

7.8
CVE-2026-55006

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privile

7.8
CVE-2026-56155 KEV

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker

7.8
CVE-2026-50405

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate

7.8
CVE-2026-62721

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate pr

7.5
CVE-2026-39363

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to

7.5
CVE-2026-40981

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co

7.4
CVE-2026-78122

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en

7.0
CVE-2025-54518

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to

6.5
CVE-2024-4147

In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p

6.5
CVE-2025-69196

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r

6.5
CVE-2026-68868

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re

5.5
CVE-2026-20107

A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could all

5.4
CVE-2025-11246

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 1

5.3
CVE-2026-16560

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the s

4.3
CVE-2026-38743

The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and Task

4.3
CVE-2026-40690

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at le

4.3
CVE-2026-37981

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows

4.3
CVE-2026-14615

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative service

2.7
CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users ca

CVE-2025-8306

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec

CVE-2026-0873

On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptob

CVE-2025-48514

Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a

CVE-2025-48517

Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to

CVE-2025-20628

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w

CVE-2024-21962

Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent

CVE-2021-46747

Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user sp

CVE-2025-31938

Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(

CVE-2026-40145

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility a

Frequently Asked Questions

What is CWE-1220?

CWE-1220 (CWE-1220) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-1220?

There are 41 CVE records associated with CWE-1220 in our database. Of these, 3 are critical severity, 16 are high severity, and 10 are medium severity.

How can I protect against CWE-1220 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1220 using AI-powered security agents.

Detect CWE-1220 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-1220 vulnerabilities across your infrastructure.

Get Started