CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 26 of 60
- CVE-2026-92603MEDIUMCVSS 6.5EG 6.52026-09-16
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message i…
- CVE-2026-92567MEDIUMCVSS 6.5EG 6.52026-09-16
TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submiss…
- CVE-2026-92468MEDIUMCVSS 6.5EG 6.52026-09-16
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{inde…
- CVE-2026-86465MEDIUMCVSS 6.5EG 6.52026-09-16
Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator…
- CVE-2026-89141MEDIUMCVSS 6.5EG 6.52026-09-15
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a u…
- CVE-2026-91770MEDIUMCVSS 6.5EG 6.52026-09-15
IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certi…
- CVE-2026-79409MEDIUMCVSS 6.5EG 6.52026-09-15
An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.
- CVE-2026-9812MEDIUMCVSS 6.5EG 6.52026-09-14
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run propert…
- CVE-2026-90534MEDIUMCVSS 6.5EG 6.52026-09-12
Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods wit…
- CVE-2026-54258MEDIUMCVSS 6.5EG 6.52026-09-11
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to di…
- CVE-2026-89252MEDIUMCVSS 6.5EG 6.52026-09-11
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's L…
- CVE-2026-9225MEDIUMCVSS 6.5EG 6.52026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v…
- CVE-2026-87809MEDIUMCVSS 6.5EG 6.52026-09-09
Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of pri…
- CVE-2026-69375MEDIUMCVSS 6.5EG 6.52026-09-08
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
- CVE-2026-81802MEDIUMCVSS 6.5EG 6.52026-09-08
Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
- CVE-2026-86489MEDIUMCVSS 6.5EG 6.52026-09-07
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
- CVE-2026-86488MEDIUMCVSS 6.5EG 6.52026-09-07
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
- CVE-2026-86408MEDIUMCVSS 6.5EG 6.52026-09-07
Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected…
- CVE-2026-86192MEDIUMCVSS 6.5EG 6.52026-09-05
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing priva…
- CVE-2026-86113MEDIUMCVSS 6.5EG 6.52026-09-05
BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite ar…
- CVE-2026-86111MEDIUMCVSS 6.5EG 6.52026-09-05
BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access…
- CVE-2026-61688MEDIUMCVSS 6.5EG 6.52026-09-04
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent …
- CVE-2026-85693MEDIUMCVSS 6.5EG 6.52026-09-04
Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-…
- CVE-2026-85624MEDIUMCVSS 6.5EG 6.52026-09-04
Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and…
- CVE-2026-85389MEDIUMCVSS 6.5EG 6.52026-09-03
Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs …
- CVE-2026-84769MEDIUMCVSS 6.5EG 6.52026-09-03
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
- CVE-2026-75035MEDIUMCVSS 6.5EG 6.52026-09-03
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authentic…
- CVE-2026-80254MEDIUMCVSS 6.5EG 6.52026-09-03
Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.
- CVE-2026-81428MEDIUMCVSS 6.5EG 6.52026-09-02
The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to o…
- CVE-2026-84205MEDIUMCVSS 6.5EG 6.52026-09-01
GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same …
- CVE-2026-75460MEDIUMCVSS 6.5EG 6.52026-08-31
XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.
- CVE-2026-19294MEDIUMCVSS 6.5EG 6.52026-08-28
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.
- CVE-2026-82271MEDIUMCVSS 6.5EG 6.52026-08-28
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename c…
- CVE-2026-17562MEDIUMCVSS 6.5EG 6.52026-08-27
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0.
- CVE-2026-81658MEDIUMCVSS 6.5EG 6.52026-08-27
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_pt…
- CVE-2026-74771MEDIUMCVSS 6.5EG 6.52026-08-26
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Informatio…
- CVE-2026-54050MEDIUMCVSS 6.5EG 6.52026-08-24
Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.rem…
- CVE-2026-71507MEDIUMCVSS 6.5EG 6.52026-08-24
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank acc…
- CVE-2026-77769MEDIUMCVSS 6.5EG 6.52026-08-21
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for th…
- CVE-2026-77768MEDIUMCVSS 6.5EG 6.52026-08-21
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carr…
- CVE-2026-63003MEDIUMCVSS 6.5EG 6.52026-08-20
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePage…
- CVE-2026-54622MEDIUMCVSS 6.5EG 6.52026-08-20
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plu…
- CVE-2026-76634MEDIUMCVSS 6.5EG 6.52026-08-20
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extra…
- CVE-2026-68559MEDIUMCVSS 6.5EG 6.52026-08-19
Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the asynchronous exporterExcel.canExport(user) authorization guard from models/server/ExporterE…
- CVE-2026-55694MEDIUMCVSS 6.5EG 6.52026-08-19
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eu…
- CVE-2026-19417MEDIUMCVSS 6.5EG 6.52026-08-19
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients…
- CVE-2026-13175MEDIUMCVSS 6.5EG 6.52026-08-19
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other u…
- CVE-2026-73395MEDIUMCVSS 6.5EG 6.52026-08-18
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
- CVE-2026-63178MEDIUMCVSS 6.5EG 6.52026-08-17
Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py call upd…
- CVE-2026-63669MEDIUMCVSS 6.5EG 6.52026-08-17
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the check …
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →