Threadlinqs IntelligenceStart free

Weakness · BaseCWE-1220

CWE-1220: Insufficient Granularity of Access Control

KEV-linkedBase

As of 2026-10-05, CWE-1220 (Insufficient Granularity of Access Control) underlies 5 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 23 tracked threats.

CVEs
5Mapped to CWE-1220
CISA KEV
2Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
23Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-1220?

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Integrated circuits and hardware engines can expose accesses to assets (device configuration, keys, etc.) to trusted firmware or a software module (commonly set by BIOS/bootloader). This access is typically access-controlled. Upon a power reset, the hardware or system usually starts with default values in registers, and the trusted firmware (Boot firmware) configures the necessary access-control protection. A common weakness that can exist in such protection schemes is that access controls or policies are not granular enough. This condition allows agents beyond trusted agents to access assets and could lead to a loss of functionality or the ability to set up the device securely. This further results in security risks from leaked, sensitive, key material to modification of device configuration.

CWE-1220 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not OS-Specific; Not Architecture-Specific; Not Technology-Specific.

Source: MITRE CWE (CWE-1220 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity, Availability, Access Control — Modify Memory, Read Memory, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, Bypass Protection Mechanism, Other

Source: MITRE CWE, common consequences.

How CWE-1220 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-1220, published between 2025-04-16 and 2026-08-22. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 3 high. The highest EPSS score in the set is 13.8% (CVE-2025-31201), the modelled probability of exploitation in the next 30 days. 23 tracked threats reference CWE-1220 directly or through a CVE it covers; the most recent is “Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters” (2026-09-03). Affected products concentrate in Microsoft (2), Apple (1), ServiceNow (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-1220, CISA KEV first, then by CVSS score.

Affected vendors

  • Microsoft — 2 CVEs
  • Apple — 1 CVE
  • ServiceNow — 1 CVE
  • Tecnativa — 1 CVE

Threat activity

23 tracked threats cite CWE-1220:

Mitigations

  • Architecture and Design, Implementation, Testing: - Access-control-policy protections must be reviewed for design inconsistency and common weaknesses. - Access-control-policy definition and programming flow must be tested in pre-silicon, post-silicon testing.

Source: MITRE CWE, potential mitigations.