CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 21 of 60
- CVE-2024-10121HIGHCVSS 7.3EG 7.32024-10-18
A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. The manipulation with the input /../ leads to authorization bypass. The atta…
- CVE-2024-2577HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to a…
- CVE-2024-2576HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorizatio…
- CVE-2024-2575HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality of the file /task-details.php. The manipulation of the argument t…
- CVE-2024-2574HIGHCVSS 7.3EG 7.32024-03-18
A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-task.php. The manipulation of the argument task_id leads t…
- CVE-2022-0624HIGHCVSS 7.3EG 7.32022-06-28
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
- CVE-2021-44160HIGHCVSS 7.3EG 7.32021-12-29
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform…
- CVE-2019-7890HIGHCVSS 7.3EG 7.32019-08-02
An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.
- CVE-2024-11146HIGHCVSS 6.3EG 7.32025-01-17
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application. P…
- CVE-2026-100612HIGHCVSS 7.2EG 7.22026-09-26
Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_prov…
- CVE-2026-97060HIGHCVSS 7.2EG 7.22026-09-25
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords fo…
- CVE-2026-77705HIGHCVSS 7.2EG 7.22026-09-12
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's …
- CVE-2026-81817HIGHCVSS 7.2EG 7.22026-08-27
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a case identifier and a task identifier, but previous…
- CVE-2026-81031HIGHCVSS 7.2EG 7.22026-08-26
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the a…
- CVE-2026-76236HIGHCVSS 7.2EG 7.22026-08-19
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, a…
- CVE-2026-56222HIGHCVSS 7.2EG 7.22026-06-23
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-scoped role binding creation. An attacker with administrative privileges in one organizati…
- CVE-2026-54097HIGHCVSS 7.2EG 7.22026-06-12
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, a low-privileged authenticated user of filebrowser (with create + delete permissions …
- CVE-2026-9851HIGHCVSS 7.2EG 7.22026-06-06
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJ…
- CVE-2026-29002HIGHCVSS 7.2EG 7.22026-04-10
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter …
- CVE-2026-32103HIGHCVSS 7.2EG 7.22026-03-11
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset-link endpoint allows any authenticated user with admin privileges to generate a password …
- CVE-2023-6317HIGHCVSS 7.2EG 7.22024-04-09
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.…
- CVE-2021-22023HIGHCVSS 7.2EG 7.22021-08-30
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an…
- CVE-2019-17050HIGHCVSS 7.2EG 7.22019-09-30
An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution …
- CVE-2024-4341HIGHCVSS 6.5EG 7.22024-07-08
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users. This issue affects Extreme XDS: before 3928.
- CVE-2023-2844HIGHCVSS 4.9EG 7.22023-05-23
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
- CVE-2026-78023HIGHCVSS 7.1EG 7.12026-10-09
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnera…
- CVE-2026-107270HIGHCVSS 7.1EG 7.12026-10-07
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequenti…
- CVE-2026-103009HIGHCVSS 7.1EG 7.12026-10-06
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an…
- CVE-2026-106100HIGHCVSS 7.1EG 7.12026-10-06
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field…
- CVE-2026-105867HIGHCVSS 7.1EG 7.12026-10-06
Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to anoth…
- CVE-2026-105847HIGHCVSS 7.1EG 7.12026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer …
- CVE-2026-105761HIGHCVSS 7.1EG 7.12026-10-05
Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by th…
- CVE-2026-105699HIGHCVSS 7.1EG 7.12026-10-05
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI suppli…
- CVE-2026-105633HIGHCVSS 7.1EG 7.12026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while ta…
- CVE-2026-105629HIGHCVSS 7.1EG 7.12026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of …
- CVE-2026-104975HIGHCVSS 7.1EG 7.12026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a memb…
- CVE-2026-104444HIGHCVSS 7.1EG 7.12026-10-02
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag fie…
- CVE-2026-64948HIGHCVSS 7.1EG 7.12026-10-01
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
- CVE-2026-103054HIGHCVSS 7.1EG 7.12026-09-30
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfol…
- CVE-2026-97685HIGHCVSS 7.1EG 7.12026-09-29
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patchin…
- CVE-2026-93538HIGHCVSS 7.1EG 7.12026-09-28
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such …
- CVE-2026-53626HIGHCVSS 7.1EG 7.12026-09-25
GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can us…
- CVE-2026-84464HIGHCVSS 7.1EG 7.12026-09-25
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specifi…
- CVE-2026-56724HIGHCVSS 7.1EG 7.12026-09-25
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked ite…
- CVE-2026-77293HIGHCVSS 7.1EG 7.12026-09-24
TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/serv…
- CVE-2026-84789HIGHCVSS 7.1EG 7.12026-09-23
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside…
- CVE-2026-84791HIGHCVSS 7.1EG 7.12026-09-23
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configu…
- CVE-2026-96271HIGHCVSS 7.1EG 7.12026-09-23
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to ge…
- CVE-2026-77426HIGHCVSS 7.1EG 7.12026-09-22
Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting it…
- CVE-2026-94462HIGHCVSS 7.1EG 7.12026-09-22
Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a …
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →