CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,433 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 45 of 49
- CVE-2026-63095MEDIUMCVSS 6.5EG 6.52026-07-17
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary…
- CVE-2026-63099MEDIUMCVSS 6.5EG 6.52026-07-17
TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash id…
- CVE-2026-63178MEDIUMCVSS 6.5EG 6.52026-08-17
Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py call upd…
- CVE-2026-63241LOWCVSS 3.1EG 3.12026-07-29
An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.
- CVE-2026-63242MEDIUMCVSS 4.3EG 4.32026-07-29
A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion recor…
- CVE-2026-63259MEDIUMCVSS 4.3EG 4.32026-07-21
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
- CVE-2026-63307MEDIUMCVSS 6.5EG 6.52026-07-17
Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.queryExistent(id, ...) without an ownership check and returns the decr…
- CVE-2026-6355MEDIUMCVSS 6.5EG 6.52026-04-22
A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive informat…
- CVE-2026-63669MEDIUMCVSS 6.5EG 6.52026-08-17
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the check …
- CVE-2026-63735HIGHCVSS 8.1EG 8.12026-07-20
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/data…
- CVE-2026-63745MEDIUMCVSS 5.4EG 5.42026-07-20
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access o…
- CVE-2026-6375HIGHCVSS 8.7EG 8.72026-04-23
A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate v…
- CVE-2026-63763HIGHCVSS 8.8EG 8.82026-07-20
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or clos…
- CVE-2026-6444HIGHCVSS 8.6EG 8.62026-06-09
A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.
- CVE-2026-64662MEDIUMCVSS 6.5EG 6.52026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom…
- CVE-2026-64927MEDIUMCVSS 6.4EG 6.42026-08-12
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (…
- CVE-2026-64961MEDIUMCVSS 6.3EG 6.32026-08-20
ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain uninitialized in certain code paths. An unauthenticated attacke…
- CVE-2026-64969MEDIUMCVSS 5.3EG 5.32026-08-20
ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST request to the profile album endpoint …
- CVE-2026-65013HIGHCVSS 8.8EG 8.82026-07-22
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API p…
- CVE-2026-65016HIGHCVSS 8.8EG 8.82026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent as…
- CVE-2026-65316MEDIUMCVSS 6.5EG 6.52026-07-21
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to t…
- CVE-2026-6541MEDIUMCVSS 4.3EG 4.32026-07-13
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook m…
- CVE-2026-6542MEDIUMCVSS 6.5EG 6.52026-04-30
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
- CVE-2026-65456MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
- CVE-2026-65463MEDIUMCVSS 5.4EG 5.42026-07-23
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
- CVE-2026-65501MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
- CVE-2026-65523HIGHCVSS 7.5EG 7.52026-08-06
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
- CVE-2026-65642HIGHCVSS 8.6EG 8.62026-08-26
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
- CVE-2026-6566MEDIUMCVSS 4.3EG 4.32026-05-20
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the…
- CVE-2026-65696MEDIUMCVSS 5.4EG 5.42026-07-23
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an …
- CVE-2026-65699MEDIUMCVSS 4.2EG 4.22026-07-23
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownershi…
- CVE-2026-6570LOWCVSS 2.7EG 2.72026-04-19
A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass…
- CVE-2026-65708HIGHCVSS 8.1EG 8.12026-07-24
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting mi…
- CVE-2026-65709HIGHCVSS 8.3EG 8.32026-07-24
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault wi…
- CVE-2026-6571MEDIUMCVSS 6.3EG 6.32026-04-19
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lea…
- CVE-2026-65710HIGHCVSS 7.1EG 7.12026-07-24
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password…
- CVE-2026-6583MEDIUMCVSS 5.4EG 5.42026-04-19
A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superagi/controllers/api_key.py of the component API Key Management Endpoint. The manipulation le…
- CVE-2026-6584MEDIUMCVSS 5.4EG 5.42026-04-20
A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update Endpoint. The manipulation of the argument use…
- CVE-2026-6585MEDIUMCVSS 5.4EG 5.42026-04-20
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organisation Update Endpoint. This manipulati…
- CVE-2026-6586MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authoriza…
- CVE-2026-65917HIGHCVSS 8.8EG 8.82026-07-23
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allo…
- CVE-2026-65981HIGHCVSS 7.1EG 7.12026-07-31
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the orig…
- CVE-2026-66013CRITICALCVSS 9.3EG 9.32026-07-25
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite…
- CVE-2026-66058MEDIUMCVSS 5.3EG 5.32026-08-07
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.
- CVE-2026-6612MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of the component Agent Execution Endpoint.…
- CVE-2026-6613MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipulation of the argument agent_id leads to…
- CVE-2026-6614MEDIUMCVSS 6.3EG 6.32026-04-20
A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulat…
- CVE-2026-66412MEDIUMCVSS 6.5EG 6.52026-07-27
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone …
- CVE-2026-66634MEDIUMCVSS 4.3EG 4.32026-08-18
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
- CVE-2026-66692MEDIUMCVSS 4.3EG 4.32026-08-06
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →