CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,981 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 5 of 60
- CVE-2026-20912CRITICALCVSS 9.1EG 9.12026-01-22
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to u…
- CVE-2026-20897CRITICALCVSS 9.1EG 9.12026-01-22
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
- CVE-2025-65021CRITICALCVSS 9.1EG 9.12025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in the poll finalization feature of the application. Any authenticated user can finalize a …
- CVE-2024-50693CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
- CVE-2024-50689CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.
- CVE-2024-50687CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model.
- CVE-2024-50686CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.
- CVE-2024-50685CRITICALCVSS 9.1EG 9.12025-02-26
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.
- CVE-2025-1270CRITICALCVSS 9.1EG 9.12025-02-13
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_dato…
- CVE-2024-49388CRITICALCVSS 9.1EG 9.12024-10-15
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
- CVE-2023-38050CRITICALCVSS 9.1EG 9.12024-07-09
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
- CVE-2024-2472CRITICALCVSS 9.1EG 9.12024-06-14
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9…
- CVE-2019-19755CRITICALCVSS 9.1EG 9.12024-04-30
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated t…
- CVE-2024-33668CRITICALCVSS 9.1EG 9.12024-04-26
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no ac…
- CVE-2024-31815CRITICALCVSS 9.1EG 9.12024-04-08
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
- CVE-2024-27302CRITICALCVSS 9.1EG 9.12024-03-06
go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allowed in CORS policy. However, the `isOriginAllowed` uses `strings.HasSuffix` to check the o…
- CVE-2023-44981CRITICALCVSS 9.1EG 9.12023-10-11
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in …
- CVE-2023-44206CRITICALCVSS 9.1EG 9.12023-09-27
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2022-36247CRITICALCVSS 9.1EG 9.12023-05-30
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
- CVE-2022-40186CRITICALCVSS 9.1EG 9.12022-09-22
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrit…
- CVE-2022-38789CRITICALCVSS 9.1EG 9.12022-09-15
An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.
- CVE-2022-1996CRITICALCVSS 9.1EG 9.12022-06-08
Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
- CVE-2022-1165CRITICALCVSS 9.1EG 9.12022-04-04
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking…
- CVE-2022-0686CRITICALCVSS 9.1EG 9.12022-02-20
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
- CVE-2021-20599CRITICALCVSS 9.1EG 9.12021-10-14
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/1…
- CVE-2019-17574CRITICALCVSS 9.1EG 9.12019-10-14
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by control…
- CVE-2019-17382CRITICALCVSS 9.1EG 9.12019-10-09
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/…
- CVE-2026-25197CRITICALCVSS 8.1EG 9.12026-04-03
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
- CVE-2024-7474CRITICALCVSS 8.1EG 9.12024-10-29
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequat…
- CVE-2024-1626CRITICALCVSS 8.1EG 9.12024-04-16
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint. The vulnerability allows authenticated users to modify the name of any project within th…
- CVE-2024-46937CRITICALCVSS 7.5EG 9.12024-09-16
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user token…
- CVE-2025-40541CRITICALCVSS 7.2EG 9.12026-02-24
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. O…
- CVE-2026-24379CRITICALCVSS 6.5EG 9.12026-01-22
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.
- CVE-2024-31095CRITICALCVSS 5.3EG 9.12024-03-31
Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0.
- CVE-2023-6144CRITICALCVSS 4.8EG 9.12023-11-21
Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
- CVE-2026-67403CRITICALCVSS 9.0EG 9.02026-09-09
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifyi…
- CVE-2026-59216CRITICALCVSS 9.0EG 9.02026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the s…
- CVE-2026-45750CRITICALCVSS 9.0EG 9.02026-06-05
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix File Manager component unsafely processe…
- CVE-2026-45746CRITICALCVSS 9.0EG 9.02026-06-05
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Termix contains a critical Broken Access Control vulnerability due to i…
- CVE-2026-5652CRITICALCVSS 9.0EG 9.02026-04-21
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
- CVE-2025-27507CRITICALCVSS 9.0EG 9.02025-03-04
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, with…
- CVE-2024-22206CRITICALCVSS 9.0EG 9.02024-01-12
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
- CVE-2026-19083HIGHCVSS 8.8EG 8.82026-10-08
Authorization bypass through User-Controlled key vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. OctoCloud allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects OctoCloud: fr…
- CVE-2026-102406HIGHCVSS 8.8EG 8.82026-10-06
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organiza…
- CVE-2026-96451HIGHCVSS 8.8EG 8.82026-10-03
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
- CVE-2026-100679HIGHCVSS 8.8EG 8.82026-09-26
stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own a…
- CVE-2026-100670HIGHCVSS 8.8EG 8.82026-09-26
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat d…
- CVE-2026-100614HIGHCVSS 8.8EG 8.82026-09-26
Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenan…
- CVE-2026-86678HIGHCVSS 8.8EG 8.82026-09-23
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
- CVE-2026-12384HIGHCVSS 8.8EG 8.82026-09-18
Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early abou…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →