CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 25 of 60
- CVE-2023-2548MEDIUMCVSS 6.6EG 6.62023-05-16
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authoriza…
- CVE-2022-0266MEDIUMCVSS 6.6EG 6.62022-01-19
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
- CVE-2026-108547MEDIUMCVSS 6.5EG 6.52026-10-10
AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared…
- CVE-2026-108164MEDIUMCVSS 6.5EG 6.52026-10-10
Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' private message attachments. Attackers c…
- CVE-2026-85571MEDIUMCVSS 6.5EG 6.52026-10-10
The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any p…
- CVE-2026-108096MEDIUMCVSS 6.5EG 6.52026-10-09
Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records owned by other users of the same applicatio…
- CVE-2026-10631MEDIUMCVSS 6.5EG 6.52026-10-08
An authorization bypass in the EWS FindItem handler of Zimbra Collaboration Suite 10.1.0 through 10.1.19 allows an authenticated user with EWS enabled to read complete mailbox items, including raw MIME and attachments, from arbitrary local…
- CVE-2026-106603MEDIUMCVSS 6.5EG 6.52026-10-08
Authorization Bypass Through User-Controlled Key vulnerability in Groundhogg HollerBox holler-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HollerBox: from n/a through 2.3.14.
- CVE-2026-94245MEDIUMCVSS 6.5EG 6.52026-10-08
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to mov…
- CVE-2026-76269MEDIUMCVSS 6.5EG 6.52026-10-07
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs t…
- CVE-2026-46438MEDIUMCVSS 6.5EG 6.52026-10-07
wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api/v…
- CVE-2026-105811MEDIUMCVSS 6.5EG 6.52026-10-06
Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md ),…
- CVE-2026-39756MEDIUMCVSS 6.5EG 6.52026-10-06
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
- CVE-2026-32576MEDIUMCVSS 6.5EG 6.52026-10-06
Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: f…
- CVE-2026-105754MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifier…
- CVE-2026-104969MEDIUMCVSS 6.5EG 6.52026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any…
- CVE-2026-104960MEDIUMCVSS 6.5EG 6.52026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access t…
- CVE-2026-104449MEDIUMCVSS 6.5EG 6.52026-10-02
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submi…
- CVE-2026-97269MEDIUMCVSS 6.5EG 6.52026-10-01
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
- CVE-2026-97251MEDIUMCVSS 6.5EG 6.52026-10-01
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
- CVE-2026-103288MEDIUMCVSS 6.5EG 6.52026-10-01
Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they …
- CVE-2026-103491MEDIUMCVSS 6.5EG 6.52026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
- CVE-2026-91109MEDIUMCVSS 6.5EG 6.52026-10-01
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. …
- CVE-2026-102139MEDIUMCVSS 6.5EG 6.52026-09-30
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature…
- CVE-2026-96347MEDIUMCVSS 6.5EG 6.52026-09-30
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
- CVE-2026-102373MEDIUMCVSS 6.5EG 6.52026-09-29
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tick…
- CVE-2026-100688MEDIUMCVSS 6.5EG 6.52026-09-26
Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source cod…
- CVE-2026-100531MEDIUMCVSS 6.5EG 6.52026-09-26
The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization …
- CVE-2026-85291MEDIUMCVSS 6.5EG 6.52026-09-25
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without a…
- CVE-2026-97636MEDIUMCVSS 6.5EG 6.52026-09-24
Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path s…
- CVE-2026-76907MEDIUMCVSS 6.5EG 6.52026-09-24
LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/documents/search/ accepts sequential seven-digit document paths to scope descendant searches without requiring the caller to…
- CVE-2026-84720MEDIUMCVSS 6.5EG 6.52026-09-23
A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent…
- CVE-2026-84713MEDIUMCVSS 6.5EG 6.52026-09-23
A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is c…
- CVE-2026-95602MEDIUMCVSS 6.5EG 6.52026-09-23
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a…
- CVE-2026-86867MEDIUMCVSS 6.5EG 6.52026-09-23
Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages…
- CVE-2026-80342MEDIUMCVSS 6.5EG 6.52026-09-23
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, al…
- CVE-2026-16264MEDIUMCVSS 6.5EG 6.52026-09-23
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscri…
- CVE-2026-75101MEDIUMCVSS 6.5EG 6.52026-09-22
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access token…
- CVE-2026-75517MEDIUMCVSS 6.5EG 6.52026-09-22
Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary loo…
- CVE-2026-94533MEDIUMCVSS 6.5EG 6.52026-09-21
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attachm…
- CVE-2026-94532MEDIUMCVSS 6.5EG 6.52026-09-21
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensitive…
- CVE-2026-55179MEDIUMCVSS 6.5EG 6.52026-09-21
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from an …
- CVE-2026-79917MEDIUMCVSS 6.5EG 6.52026-09-21
MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_u…
- CVE-2026-61744MEDIUMCVSS 6.5EG 6.52026-09-21
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenti…
- CVE-2026-89333MEDIUMCVSS 6.5EG 6.52026-09-19
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…
- CVE-2026-93660MEDIUMCVSS 6.5EG 6.52026-09-18
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to r…
- CVE-2026-92714MEDIUMCVSS 6.5EG 6.52026-09-18
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic '…
- CVE-2026-85009MEDIUMCVSS 6.5EG 6.52026-09-18
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable …
- CVE-2026-92765MEDIUMCVSS 6.5EG 6.52026-09-16
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to ret…
- CVE-2026-92605MEDIUMCVSS 6.5EG 6.52026-09-16
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and rea…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →