What is CWE-1220?
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Integrated circuits and hardware engines can expose accesses to assets (device configuration, keys, etc.) to trusted firmware or a software module (commonly set by BIOS/bootloader). This access is typically access-controlled. Upon a power reset, the hardware or system usually starts with default values in registers, and the trusted firmware (Boot firmware) configures the necessary access-control protection. A common weakness that can exist in such protection schemes is that access controls or policies are not granular enough. This condition allows agents beyond trusted agents to access assets and could lead to a loss of functionality or the ability to set up the device securely. This further results in security risks from leaked, sensitive, key material to modification of device configuration.
CWE-1220 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not OS-Specific; Not Architecture-Specific; Not Technology-Specific.
Source: MITRE CWE (CWE-1220 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality, Integrity, Availability, Access Control — Modify Memory, Read Memory, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, Bypass Protection Mechanism, Other
Source: MITRE CWE, common consequences.
How CWE-1220 is exploited in the wild
Threadlinqs maps 5 CVEs to CWE-1220, published between 2025-04-16 and 2026-08-22. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 3 high. The highest EPSS score in the set is 13.8% (CVE-2025-31201), the modelled probability of exploitation in the next 30 days. 23 tracked threats reference CWE-1220 directly or through a CVE it covers; the most recent is “Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters” (2026-09-03). Affected products concentrate in Microsoft (2), Apple (1), ServiceNow (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 5 CVEs mapped to CWE-1220, CISA KEV first, then by CVSS score.
- CVE-2025-31201 — CISA KEV · CVSS 9.8 critical · EPSS 13.8% · published 2025-04-16
- CVE-2026-56155 — CISA KEV · CVSS 7.8 high · published 2026-07-14
- CVE-2026-40365 — CVSS 8.8 high · EPSS 0.0% · published 2026-05-12
- CVE-2026-78122 — CVSS 7.4 high · EPSS 0.3% · published 2026-08-22
- CVE-2025-3648 — EPSS 1.6% · published 2025-07-08
Affected vendors
Threat activity
23 tracked threats cite CWE-1220:
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student ProtestersHIGH
- NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World IntrusionsCRITICAL
- Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances (CVE-2025-3648 "Count(er) Strike" Context)MEDIUM
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ FixesHIGH
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-DaysCRITICAL
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance Takeover Alongside Microsoft July 2026 Patch Tuesday (570 CVEs, 3 Zero-Days incl. SharePoint & AD FS EoP)CRITICAL
- CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-DayMEDIUM
- CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively ExploitedHIGH
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)CRITICAL
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEVCRITICAL
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)CRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege EscalationCRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)CRITICAL
- Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly DisclosedHIGH
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)CRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)HIGH
- Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)CRITICAL
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)CRITICAL
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)CRITICAL
- July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040HIGH
- Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon Stack Overflow on Domain ControllersHIGH
- CVE-2026-33825: Microsoft Defender Local Privilege Escalation via BlueHammer TOCTOU Race ConditionHIGH
Mitigations
- Architecture and Design, Implementation, Testing: - Access-control-policy protections must be reviewed for design inconsistency and common weaknesses. - Access-control-policy definition and programming flow must be tested in pre-silicon, post-silicon testing.
Source: MITRE CWE, potential mitigations.