CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,433 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 48 of 49
- CVE-2026-7638MEDIUMCVSS 5.3EG 5.32026-05-02
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `u…
- CVE-2026-76397HIGHCVSS 8.1EG 8.12026-08-19
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk A…
- CVE-2026-7648MEDIUMCVSS 4.3EG 4.32026-05-14
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. This is due to improper handling of us…
- CVE-2026-7651MEDIUMCVSS 5.3EG 5.32026-05-28
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio…
- CVE-2026-76634MEDIUMCVSS 6.5EG 6.52026-08-20
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extra…
- CVE-2026-76647HIGHCVSS 8.8EG 8.82026-08-19
Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer me…
- CVE-2026-7665MEDIUMCVSS 5.3EG 5.32026-06-06
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restric…
- CVE-2026-7681MEDIUMCVSS 6.5EG 6.52026-05-03
A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the file backend/webserver/api/datasets.py of the component Dataset API. The manipulation of t…
- CVE-2026-7702MEDIUMCVSS 5.3EG 5.32026-05-03
A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId/:docId of the component Public Markdown Preview Endpoint. The manipulation results in aut…
- CVE-2026-77035MEDIUMCVSS 5.1EG 5.12026-08-27
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST anothe…
- CVE-2026-77073MEDIUMCVSS 5.3EG 5.32026-08-20
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID…
- CVE-2026-77079HIGHCVSS 7.4EG 7.42026-08-20
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and…
- CVE-2026-77081MEDIUMCVSS 5.1EG 5.12026-08-20
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is trea…
- CVE-2026-77116MEDIUMCVSS 4.3EG 4.32026-08-23
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by pass…
- CVE-2026-77127MEDIUMCVSS 6.0EG 6.02026-08-25
The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and t…
- CVE-2026-77135HIGHCVSS 8.2EG 8.22026-08-25
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, inclu…
- CVE-2026-77140HIGHCVSS 8.7EG 8.72026-08-25
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send…
- CVE-2026-77141HIGHCVSS 8.8EG 8.82026-08-25
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a clu…
- CVE-2026-77142HIGHCVSS 8.8EG 8.82026-08-25
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on th…
- CVE-2026-77143HIGHCVSS 8.8EG 8.82026-08-25
The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update req…
- CVE-2026-77145HIGHCVSS 7.1EG 7.12026-08-25
The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.
- CVE-2026-77368HIGHCVSS 7.6EG 7.62026-08-26
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tena…
- CVE-2026-77759HIGHCVSS 8.7EG 8.72026-08-21
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identi…
- CVE-2026-77768MEDIUMCVSS 6.5EG 6.52026-08-21
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carr…
- CVE-2026-77769MEDIUMCVSS 6.5EG 6.52026-08-21
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for th…
- CVE-2026-77776CRITICALCVSS 9.1EG 9.12026-08-21
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing bi…
- CVE-2026-77780MEDIUMCVSS 5.3EG 5.32026-08-21
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank accoun…
- CVE-2026-77789MEDIUMCVSS 4.3EG 4.32026-08-26
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal…
- CVE-2026-7782MEDIUMCVSS 6.3EG 6.32026-05-04
A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the file application/controllers/Clients.php of the component Tenant Handler. The manipulation of the argument ID results in a…
- CVE-2026-7787HIGHCVSS 8.1EG 8.12026-06-11
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
- CVE-2026-77990MEDIUMCVSS 5.3EG 5.32026-08-27
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not …
- CVE-2026-77995CRITICALCVSS 10.0EG 10.02026-08-24
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
- CVE-2026-77998CRITICALCVSS 10.0EG 10.02026-08-25
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google …
- CVE-2026-78139MEDIUMCVSS 4.3EG 4.32026-08-27
The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-lev…
- CVE-2026-78142MEDIUMCVSS 6.3EG 6.32026-08-23
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the argument resident_id …
- CVE-2026-78144MEDIUMCVSS 6.3EG 6.32026-08-23
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipu…
- CVE-2026-78160MEDIUMCVSS 6.3EG 6.32026-08-24
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorizati…
- CVE-2026-78203HIGHCVSS 7.1EG 7.12026-08-24
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template pri…
- CVE-2026-78278MEDIUMCVSS 5.3EG 5.32026-08-24
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
- CVE-2026-78365CRITICALCVSS 9.3EG 9.32026-08-24
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own compan…
- CVE-2026-78581MEDIUMCVSS 4.2EG 4.22026-08-25
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could r…
- CVE-2026-7881MEDIUMCVSS 4.3EG 4.32026-05-21
Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS s…
- CVE-2026-7886MEDIUMCVSS 4.3EG 4.32026-05-21
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file …
- CVE-2026-79654MEDIUMCVSS 4.3EG 4.32026-08-26
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may…
- CVE-2026-80049HIGHCVSS 8.8EG 8.82026-08-25
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and Authentic…
- CVE-2026-80197MEDIUMCVSS 4.3EG 4.32026-08-25
Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries fro…
- CVE-2026-8027MEDIUMCVSS 4.3EG 4.32026-05-06
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/emai…
- CVE-2026-81031HIGHCVSS 7.2EG 7.22026-08-26
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the a…
- CVE-2026-8155MEDIUMCVSS 5.4EG 5.42026-07-31
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
- CVE-2026-81576HIGHCVSS 7.7EG 7.72026-08-27
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's hand…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →