CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,983 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 16 of 60
- CVE-2026-100514HIGHCVSS 7.5EG 7.52026-10-01
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
- CVE-2026-93882HIGHCVSS 7.5EG 7.52026-10-01
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items…
- CVE-2026-100610HIGHCVSS 7.5EG 7.52026-09-26
Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns Upser…
- CVE-2026-92577HIGHCVSS 7.5EG 7.52026-09-16
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by th…
- CVE-2026-89063HIGHCVSS 7.5EG 7.52026-09-16
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…
- CVE-2026-88065HIGHCVSS 7.5EG 7.52026-09-15
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/phot…
- CVE-2026-91144HIGHCVSS 7.5EG 7.52026-09-14
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the s…
- CVE-2026-89262HIGHCVSS 7.5EG 7.52026-09-11
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments…
- CVE-2026-79324HIGHCVSS 7.5EG 7.52026-09-09
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses …
- CVE-2026-85182HIGHCVSS 7.5EG 7.52026-09-03
vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's…
- CVE-2026-75415HIGHCVSS 7.5EG 7.52026-08-26
AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identit…
- CVE-2026-76216HIGHCVSS 7.5EG 7.52026-08-19
Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share JW…
- CVE-2026-14861HIGHCVSS 7.5EG 7.52026-08-19
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthentica…
- CVE-2026-51367HIGHCVSS 7.5EG 7.52026-08-19
An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter
- CVE-2026-55178HIGHCVSS 7.5EG 7.52026-08-18
GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a s…
- CVE-2026-75105HIGHCVSS 7.5EG 7.52026-08-17
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId para…
- CVE-2026-72545HIGHCVSS 7.5EG 7.52026-08-11
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authe…
- CVE-2026-72543HIGHCVSS 7.5EG 7.52026-08-11
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterK…
- CVE-2026-19424HIGHCVSS 7.5EG 7.52026-08-11
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
- CVE-2026-72689HIGHCVSS 7.5EG 7.52026-08-10
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches docu…
- CVE-2026-13399HIGHCVSS 7.5EG 7.52026-08-06
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
- CVE-2026-10599HIGHCVSS 7.5EG 7.52026-08-06
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, a…
- CVE-2026-65523HIGHCVSS 7.5EG 7.52026-08-06
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
- CVE-2026-69250HIGHCVSS 7.5EG 7.52026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a ser…
- CVE-2026-68500HIGHCVSS 7.5EG 7.52026-07-30
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters…
- CVE-2026-13178HIGHCVSS 7.5EG 7.52026-07-30
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
- CVE-2025-60931HIGHCVSS 7.5EG 7.52026-07-29
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET re…
- CVE-2026-59539HIGHCVSS 7.5EG 7.52026-07-27
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
- CVE-2026-43977HIGHCVSS 7.5EG 7.52026-07-16
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ ac…
- CVE-2026-15637HIGHCVSS 7.5EG 7.52026-07-14
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential…
- CVE-2026-14165HIGHCVSS 7.5EG 7.52026-07-13
An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.
- CVE-2026-1989HIGHCVSS 7.5EG 7.52026-07-09
Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects PAVO Pay: through 09072026. NOTE: The vendor was contacted…
- CVE-2026-5799HIGHCVSS 7.5EG 7.52026-07-07
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
- CVE-2026-5730HIGHCVSS 7.5EG 7.52026-07-07
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
- CVE-2026-46585HIGHCVSS 7.5EG 7.52026-07-06
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose val…
- CVE-2026-27657HIGHCVSS 7.5EG 7.52026-07-03
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
- CVE-2026-56780HIGHCVSS 7.5EG 7.52026-06-29
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can…
- CVE-2026-56069HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
- CVE-2026-54839HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.
- CVE-2026-52799HIGHCVSS 7.5EG 7.52026-06-22
Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository.…
- CVE-2026-52699HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
- CVE-2026-48868HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
- CVE-2026-48872HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
- CVE-2025-59133HIGHCVSS 7.5EG 7.52026-06-15
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
- CVE-2026-9185HIGHCVSS 7.5EG 7.52026-06-09
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_pr…
- CVE-2026-41084HIGHCVSS 7.5EG 7.52026-06-01
A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the `dag_id` / `dag_run_…
- CVE-2026-42736HIGHCVSS 7.5EG 7.52026-05-27
Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a throug…
- CVE-2026-8679HIGHCVSS 7.5EG 7.52026-05-22
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controll…
- CVE-2025-13479HIGHCVSS 7.5EG 7.52026-05-21
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers. This issue affects QR Menu: through 21052026. NOTE: The vendor was contac…
- CVE-2026-45398HIGHCVSS 7.5EG 7.52026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name prefixes but does not check knowledge base…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →