CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,433 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 43 of 49
- CVE-2026-55881HIGHCVSS 7.1EG 7.12026-07-10
OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAc…
- CVE-2026-56013MEDIUMCVSS 6.5EG 6.52026-06-25
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
- CVE-2026-56048MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
- CVE-2026-56069HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
- CVE-2026-56093MEDIUMCVSS 6.3EG 6.32026-08-25
The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve …
- CVE-2026-56147HIGHCVSS 7.1EG 7.12026-07-21
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authori…
- CVE-2026-5617HIGHCVSS 8.8EG 8.82026-04-15
The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to d…
- CVE-2026-56215HIGHCVSS 8.3EG 8.32026-06-20
Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim…
- CVE-2026-56222HIGHCVSS 7.2EG 7.22026-06-23
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-scoped role binding creation. An attacker with administrative privileges in one organizati…
- CVE-2026-56229MEDIUMCVSS 6.5EG 6.52026-06-21
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access build jobs belonging to different applications by supplying a mismatched app_id and job_id …
- CVE-2026-56230HIGHCVSS 8.8EG 8.82026-07-01
Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-id header without validating ownership, allowing authenticated users to adopt cross-tenant…
- CVE-2026-56385MEDIUMCVSS 4.3EG 4.32026-06-21
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing…
- CVE-2026-56422CRITICALCVSS 9.4EG 9.42026-06-22
Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uui…
- CVE-2026-56424HIGHCVSS 8.8EG 8.82026-06-22
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged auth…
- CVE-2026-5652CRITICALCVSS 9.0EG 9.02026-04-21
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
- CVE-2026-56721HIGHCVSS 8.8EG 8.82026-08-11
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a paramete…
- CVE-2026-56765CRITICALCVSS 9.8EG 9.82026-07-10
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permis…
- CVE-2026-56772MEDIUMCVSS 4.3EG 4.32026-06-25
NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verif…
- CVE-2026-56774MEDIUMCVSS 5.4EG 5.42026-06-25
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remembe…
- CVE-2026-56780HIGHCVSS 7.5EG 7.52026-06-29
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can…
- CVE-2026-56781MEDIUMCVSS 5.3EG 5.32026-06-29
Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the share view records en…
- CVE-2026-56784HIGHCVSS 8.1EG 8.32026-06-23
OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary a…
- CVE-2026-56823MEDIUMCVSS 5.4EG 5.42026-06-26
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary ke…
- CVE-2026-57205MEDIUMCVSS 4.3EG 4.32026-07-16
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoint…
- CVE-2026-5730HIGHCVSS 7.5EG 7.52026-07-07
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
- CVE-2026-57341MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
- CVE-2026-57494HIGHCVSS 7.1EG 7.12026-06-18
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target a…
- CVE-2026-57498CRITICALCVSS 9.6EG 9.62026-06-29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any oper…
- CVE-2026-5750HIGHCVSS 7.6EG 7.62026-04-22
An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging to other registered users through various vulnerable authenticated resources in the applic…
- CVE-2026-57510HIGHCVSS 8.8EG 8.82026-07-28
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other orga…
- CVE-2026-57630MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
- CVE-2026-57634MEDIUMCVSS 4.3EG 4.32026-06-26
Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.
- CVE-2026-57646MEDIUMCVSS 5.4EG 5.42026-06-26
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
- CVE-2026-57652MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
- CVE-2026-57665MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
- CVE-2026-57676MEDIUMCVSS 4.3EG 4.32026-06-29
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
- CVE-2026-57680MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
- CVE-2026-57694MEDIUMCVSS 6.5EG 6.52026-07-13
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.
- CVE-2026-57868HIGHCVSS 7.1EG 7.12026-07-07
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57869HIGHCVSS 7.1EG 7.12026-07-07
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects Micr…
- CVE-2026-57870MEDIUMCVSS 5.3EG 5.32026-07-07
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57886MEDIUMCVSS 5.9EG 5.92026-07-21
Cross-repository issue/comment attachment re-linking can expose private attachment content
- CVE-2026-57943MEDIUMCVSS 5.9EG 5.92026-06-29
LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation…
- CVE-2026-57945MEDIUMCVSS 4.3EG 4.32026-06-29
PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit t…
- CVE-2026-57956MEDIUMCVSS 6.4EG 6.42026-06-29
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organizat…
- CVE-2026-5798HIGHCVSS 7.1EG 7.12026-05-14
Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulner…
- CVE-2026-5799HIGHCVSS 7.5EG 7.52026-07-07
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
- CVE-2026-58410HIGHCVSS 7.1EG 7.12026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated …
- CVE-2026-5842HIGHCVSS 7.3EG 7.32026-04-09
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The atta…
- CVE-2026-58432MEDIUMCVSS 5.9EG 5.92026-07-21
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →