CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,978 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 3 of 60
- CVE-2023-51502CRITICALCVSS 9.8EG 9.82024-01-05
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.
- CVE-2023-6929CRITICALCVSS 9.8EG 9.82023-12-19
EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attacker…
- CVE-2023-38965CRITICALCVSS 9.8EG 9.82023-11-03
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
- CVE-2023-43668CRITICALCVSS 9.8EG 9.82023-10-16
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile"..…
- CVE-2023-2958CRITICALCVSS 9.8EG 9.82023-07-17
Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass. This issue affects ATS Pro: before 20230714.
- CVE-2023-37242CRITICALCVSS 9.8EG 9.82023-07-06
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilitie…
- CVE-2023-3048CRITICALCVSS 9.8EG 9.82023-06-13
Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15.
- CVE-2023-2713CRITICALCVSS 9.8EG 9.82023-05-20
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23…
- CVE-2023-2276CRITICALCVSS 9.8EG 9.82023-05-20
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controll…
- CVE-2022-4686CRITICALCVSS 9.8EG 9.82022-12-23
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2021-4226CRITICALCVSS 9.8EG 9.82022-12-15
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
- CVE-2022-31692CRITICALCVSS 9.8EG 9.82022-10-31
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: …
- CVE-2022-36202CRITICALCVSS 9.8EG 9.82022-08-31
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
- CVE-2022-1245CRITICALCVSS 9.8EG 9.82022-07-08
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target…
- CVE-2022-30495CRITICALCVSS 9.8EG 9.82022-05-26
In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)
- CVE-2022-0691CRITICALCVSS 9.8EG 9.82022-02-21
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
- CVE-2022-22832CRITICALCVSS 9.8EG 9.82022-02-06
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
- CVE-2021-45428CRITICALCVSS 9.8EG 9.82022-01-03
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
- CVE-2021-44949CRITICALCVSS 9.8EG 9.82021-12-14
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
- CVE-2021-41301CRITICALCVSS 9.8EG 9.82021-09-30
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information an…
- CVE-2021-37184CRITICALCVSS 9.8EG 9.82021-09-14
A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of any user in the system under certain circumstances. With this an attacker could impersona…
- CVE-2021-32744CRITICALCVSS 9.8EG 9.82021-07-21
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor…
- CVE-2020-16088CRITICALCVSS 9.8EG 9.82020-07-28
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
- CVE-2019-15310CRITICALCVSS 9.8EG 9.82020-07-01
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate,…
- CVE-2020-11658CRITICALCVSS 9.8EG 9.82020-04-15
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
- CVE-2019-15913CRITICALCVSS 9.8EG 9.82019-12-20
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take …
- CVE-2019-16340CRITICALCVSS 9.8EG 9.82019-11-21
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
- CVE-2019-13360CRITICALCVSS 9.8EG 9.82019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
- CVE-2019-12866CRITICALCVSS 9.8EG 9.82019-07-03
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
- CVE-2019-9756CRITICALCVSS 9.8EG 9.82019-04-17
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control, a different vulnerability than CVE-2019-…
- CVE-2023-0558CRITICALCVSS 8.2EG 9.82023-01-27
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers …
- CVE-2020-37094CRITICALCVSS 8.1EG 9.82026-02-03
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentic…
- CVE-2023-53930CRITICALCVSS 7.5EG 9.82025-12-17
ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changi…
- CVE-2026-105637CRITICALCVSS 9.6EG 9.62026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with p…
- CVE-2026-101084CRITICALCVSS 9.6EG 9.62026-09-27
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks t…
- CVE-2026-92716CRITICALCVSS 9.6EG 9.62026-09-16
Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with ad…
- CVE-2026-82870CRITICALCVSS 9.6EG 9.62026-08-31
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing orga…
- CVE-2026-53546CRITICALCVSS 9.6EG 9.62026-08-19
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that…
- CVE-2026-53548CRITICALCVSS 9.6EG 9.62026-08-19
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user'…
- CVE-2026-73644CRITICALCVSS 9.6EG 9.62026-08-13
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privileg…
- CVE-2026-72737CRITICALCVSS 9.6EG 9.62026-08-10
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and …
- CVE-2026-72564CRITICALCVSS 9.6EG 9.62026-08-10
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.
- CVE-2026-17349CRITICALCVSS 9.6EG 9.62026-07-31
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including use…
- CVE-2026-16624CRITICALCVSS 9.6EG 9.62026-07-22
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails an…
- CVE-2026-53552CRITICALCVSS 9.6EG 9.62026-07-07
Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from …
- CVE-2026-10140CRITICALCVSS 9.6EG 9.62026-06-30
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to …
- CVE-2026-57498CRITICALCVSS 9.6EG 9.62026-06-29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any oper…
- CVE-2026-12411CRITICALCVSS 9.6EG 9.62026-06-26
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security…
- CVE-2026-55518CRITICALCVSS 9.6EG 9.62026-06-17
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actua…
- CVE-2026-46441CRITICALCVSS 9.6EG 9.62026-06-08
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users …
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →