CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 24 of 60
- CVE-2019-18998HIGHCVSS 7.1EG 7.12020-02-17
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's UR…
- CVE-2026-53863HIGHCVSS 6.5EG 7.12026-06-16
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions …
- CVE-2025-52670HIGHCVSS 6.5EG 7.12025-11-20
Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts
- CVE-2024-4154HIGHCVSS 6.5EG 7.12024-05-21
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint wi…
- CVE-2026-32589HIGHCVSS 6.3EG 7.12026-04-08
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they d…
- CVE-2023-50342HIGHCVSS 4.3EG 7.12024-01-03
HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result of improper access control.
- CVE-2025-3519HIGHCVSS 7.0EG 7.02025-04-22
An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Every uploaded file in Unblu gets assigned with a randomly generated Universally Unique ID (UUID). In case a particip…
- CVE-2026-97070MEDIUMCVSS 6.9EG 6.92026-10-05
Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23.
- CVE-2026-97305MEDIUMCVSS 6.9EG 6.92026-10-05
Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPres…
- CVE-2026-87739MEDIUMCVSS 6.9EG 6.92026-09-24
An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and g…
- CVE-2026-75951MEDIUMCVSS 6.9EG 6.92026-08-19
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
- CVE-2026-75950MEDIUMCVSS 6.9EG 6.92026-08-19
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3…
- CVE-2026-59240MEDIUMCVSS 6.9EG 6.92026-07-27
The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authenticated user, regardless of company or perm…
- CVE-2026-59237MEDIUMCVSS 6.9EG 6.92026-07-16
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belo…
- CVE-2026-59236MEDIUMCVSS 6.9EG 6.92026-07-15
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to cre…
- CVE-2026-52837MEDIUMCVSS 6.9EG 6.92026-07-14
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer r…
- CVE-2026-59234MEDIUMCVSS 6.9EG 6.92026-07-03
Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 al…
- CVE-2026-53726MEDIUMCVSS 6.9EG 6.92026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation fiel…
- CVE-2026-44207MEDIUMCVSS 6.9EG 6.92026-06-12
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0…
- CVE-2026-46390MEDIUMCVSS 6.9EG 6.92026-06-05
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is exposed to unauthenticated users, allowing unauthenticated browsing of git repositories and g…
- CVE-2026-47378MEDIUMCVSS 6.9EG 6.92026-06-05
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view owner had hidden, via three independent paths: groupBy returned raw values for any column…
- CVE-2026-46721MEDIUMCVSS 6.9EG 6.92026-05-19
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly regis…
- CVE-2026-1664MEDIUMCVSS 6.9EG 6.92026-02-03
Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK. The issue occurs because the `Message-ID` and `References` headers are parsed to derive t…
- CVE-2024-22439MEDIUMCVSS 6.9EG 6.92024-04-15
A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to gain privileged access to switches resulting in information disclosure.
- CVE-2026-104898MEDIUMCVSS 6.8EG 6.82026-10-10
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.4 via the 'id, wp_user_id' parameter due to missing validation …
- CVE-2026-108110MEDIUMCVSS 6.8EG 6.82026-10-09
MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's o…
- CVE-2026-104964MEDIUMCVSS 6.8EG 6.82026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL but loads the target project globally by UUID without binding it to that w…
- CVE-2026-100609MEDIUMCVSS 6.8EG 6.82026-09-26
Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in several code paths: …
- CVE-2026-5006MEDIUMCVSS 6.8EG 6.82026-08-24
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An a…
- CVE-2026-72666MEDIUMCVSS 6.8EG 6.82026-08-13
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not …
- CVE-2026-55411MEDIUMCVSS 6.8EG 6.82026-06-25
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plainte…
- CVE-2026-45810MEDIUMCVSS 6.8EG 6.82026-06-01
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment,…
- CVE-2026-4630MEDIUMCVSS 6.8EG 6.82026-05-19
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUI…
- CVE-2026-6008MEDIUMCVSS 6.8EG 6.82026-05-14
Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.1…
- CVE-2026-42291MEDIUMCVSS 6.8EG 6.82026-05-08
SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for personal notes is not properly authorized. This allows authenticated atta…
- CVE-2026-1753MEDIUMCVSS 6.8EG 6.82026-03-11
The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
- CVE-2025-9520MEDIUMCVSS 6.8EG 6.82026-01-26
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
- CVE-2025-12351MEDIUMCVSS 6.8EG 6.82025-10-27
Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeyw…
- CVE-2024-13063MEDIUMCVSS 6.8EG 6.82025-09-03
Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issue affects MyRezzta: from s2.02.02 before v2.05.01.
- CVE-2025-6534MEDIUMCVSS 6.8EG 6.82025-06-24
A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the co…
- CVE-2021-37577MEDIUMCVSS 6.8EG 6.82024-10-01
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey…
- CVE-2024-3035MEDIUMCVSS 6.8EG 6.82024-08-08
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.
- CVE-2023-46446MEDIUMCVSS 6.8EG 6.82023-11-14
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
- CVE-2023-30550MEDIUMCVSS 6.8EG 6.82023-05-04
MeterSphere is an open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing, and performance testing. This IDOR vulnerability allows the administrator of a project to modify other proj…
- CVE-2021-21324MEDIUMCVSS 6.8EG 6.82021-03-08
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 there is an Insecure Direct Object Reference (IDOR) on "Solutio…
- CVE-2024-47495MEDIUMCVSS 6.7EG 6.72024-10-11
An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing Engines (REs) are in use on Juniper Networks Junos OS Evolved …
- CVE-2023-26237MEDIUMCVSS 6.7EG 6.72023-10-05
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
- CVE-2023-27576MEDIUMCVSS 6.7EG 6.72023-08-18
An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission. Specifi…
- CVE-2026-32694MEDIUMCVSS 6.6EG 6.62026-03-18
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious grantee which c…
- CVE-2025-24976MEDIUMCVSS 6.6EG 6.62025-02-11
Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication …
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →