CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 27 of 60
- CVE-2026-13358MEDIUMCVSS 6.5EG 6.52026-08-16
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to mi…
- CVE-2026-72657MEDIUMCVSS 6.5EG 6.52026-08-13
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-suppl…
- CVE-2026-28155MEDIUMCVSS 6.5EG 6.52026-08-13
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
- CVE-2026-73616MEDIUMCVSS 6.5EG 6.52026-08-13
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remov…
- CVE-2026-73488MEDIUMCVSS 6.5EG 6.52026-08-13
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile dat…
- CVE-2026-18744MEDIUMCVSS 6.5EG 6.52026-08-12
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks e…
- CVE-2026-73239MEDIUMCVSS 6.5EG 6.52026-08-12
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the …
- CVE-2026-69117MEDIUMCVSS 6.5EG 6.52026-08-11
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON …
- CVE-2026-72774MEDIUMCVSS 6.5EG 6.52026-08-11
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credent…
- CVE-2026-72763MEDIUMCVSS 6.5EG 6.52026-08-11
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with Editor access to a sha…
- CVE-2026-69114MEDIUMCVSS 6.5EG 6.52026-08-10
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MANAG…
- CVE-2026-68872MEDIUMCVSS 6.5EG 6.52026-08-10
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment …
- CVE-2026-68871MEDIUMCVSS 6.5EG 6.52026-08-10
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this …
- CVE-2026-19077MEDIUMCVSS 6.5EG 6.52026-08-10
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.…
- CVE-2026-70561MEDIUMCVSS 6.5EG 6.52026-08-07
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the att…
- CVE-2026-16039MEDIUMCVSS 6.5EG 6.52026-08-07
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each…
- CVE-2026-64662MEDIUMCVSS 6.5EG 6.52026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom…
- CVE-2026-70557MEDIUMCVSS 6.5EG 6.52026-08-06
diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist. The only guard, relatedDataSecurit…
- CVE-2026-18275MEDIUMCVSS 6.5EG 6.52026-08-06
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their…
- CVE-2026-48912MEDIUMCVSS 6.5EG 6.52026-08-05
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supp…
- CVE-2026-71251MEDIUMCVSS 6.5EG 6.52026-08-05
Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to…
- CVE-2026-11454MEDIUMCVSS 6.5EG 6.52026-08-05
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The en…
- CVE-2026-68582MEDIUMCVSS 6.5EG 6.52026-08-02
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view fro…
- CVE-2026-15209MEDIUMCVSS 6.5EG 6.52026-07-31
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the r…
- CVE-2026-68501MEDIUMCVSS 6.5EG 6.52026-07-30
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAc…
- CVE-2026-10700MEDIUMCVSS 6.5EG 6.52026-07-30
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce aut…
- CVE-2026-5060MEDIUMCVSS 6.5EG 6.52026-07-29
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` func…
- CVE-2026-66412MEDIUMCVSS 6.5EG 6.52026-07-27
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone …
- CVE-2026-69160MEDIUMCVSS 6.5EG 6.52026-07-24
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) without enforcing a directory separator bou…
- CVE-2026-17059MEDIUMCVSS 6.5EG 6.52026-07-24
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has p…
- CVE-2026-47755MEDIUMCVSS 6.5EG 6.52026-07-23
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another c…
- CVE-2026-61946MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
- CVE-2026-2406MEDIUMCVSS 6.5EG 6.52026-07-22
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online…
- CVE-2026-65316MEDIUMCVSS 6.5EG 6.52026-07-21
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to t…
- CVE-2026-15342MEDIUMCVSS 6.5EG 6.52026-07-21
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspac…
- CVE-2026-45295MEDIUMCVSS 6.5EG 6.52026-07-20
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthenticated attackers to enumerate valid co…
- CVE-2026-63307MEDIUMCVSS 6.5EG 6.52026-07-17
Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.queryExistent(id, ...) without an ownership check and returns the decr…
- CVE-2026-11763MEDIUMCVSS 6.5EG 6.52026-07-17
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue …
- CVE-2026-63099MEDIUMCVSS 6.5EG 6.52026-07-17
TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash id…
- CVE-2026-63095MEDIUMCVSS 6.5EG 6.52026-07-17
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary…
- CVE-2026-11889MEDIUMCVSS 6.5EG 6.52026-07-16
SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.
- CVE-2026-53447MEDIUMCVSS 6.5EG 6.52026-07-15
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or chec…
- CVE-2026-59259MEDIUMCVSS 6.5EG 6.52026-07-15
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with…
- CVE-2025-32781MEDIUMCVSS 6.5EG 6.52026-07-13
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a re…
- CVE-2026-57694MEDIUMCVSS 6.5EG 6.52026-07-13
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.
- CVE-2026-49296MEDIUMCVSS 6.5EG 6.52026-07-07
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the …
- CVE-2026-59098MEDIUMCVSS 6.5EG 6.52026-07-02
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to access other users' data by exploiting missing user-identifier…
- CVE-2026-57680MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
- CVE-2026-5135MEDIUMCVSS 6.5EG 6.52026-07-01
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field …
- CVE-2026-5142MEDIUMCVSS 6.5EG 6.52026-07-01
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulner…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →