CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
1,967 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 37 of 40
- CVE-2026-55880HIGHCVSS 7.1EG 7.12026-07-10
OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only o…
- CVE-2026-55881HIGHCVSS 7.1EG 7.12026-07-10
OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAc…
- CVE-2026-56013MEDIUMCVSS 6.5EG 6.52026-06-25
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
- CVE-2026-56048MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
- CVE-2026-56069HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
- CVE-2026-56147HIGHCVSS 7.1EG 7.12026-07-21
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authori…
- CVE-2026-5617HIGHCVSS 8.8EG 8.82026-04-15
The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to d…
- CVE-2026-56215HIGHCVSS 8.3EG 8.32026-06-20
Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim…
- CVE-2026-56222HIGHCVSS 7.2EG 7.22026-06-23
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-scoped role binding creation. An attacker with administrative privileges in one organizati…
- CVE-2026-56229MEDIUMCVSS 6.5EG 6.52026-06-21
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access build jobs belonging to different applications by supplying a mismatched app_id and job_id …
- CVE-2026-56230HIGHCVSS 8.8EG 8.82026-07-01
Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-id header without validating ownership, allowing authenticated users to adopt cross-tenant…
- CVE-2026-56385MEDIUMCVSS 4.3EG 4.32026-06-21
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing…
- CVE-2026-56422CRITICALCVSS 9.4EG 9.42026-06-22
Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uui…
- CVE-2026-56424HIGHCVSS 8.8EG 8.82026-06-22
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged auth…
- CVE-2026-5652CRITICALCVSS 9.0EG 9.02026-04-21
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
- CVE-2026-56765CRITICALCVSS 9.8EG 9.82026-07-10
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permis…
- CVE-2026-56772MEDIUMCVSS 4.3EG 4.32026-06-25
NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verif…
- CVE-2026-56774MEDIUMCVSS 5.4EG 5.42026-06-25
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remembe…
- CVE-2026-56780HIGHCVSS 7.5EG 7.52026-06-29
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can…
- CVE-2026-56781MEDIUMCVSS 5.3EG 5.32026-06-29
Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the share view records en…
- CVE-2026-56784HIGHCVSS 8.1EG 8.32026-06-23
OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary a…
- CVE-2026-56823MEDIUMCVSS 5.4EG 5.42026-06-26
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary ke…
- CVE-2026-57205MEDIUMCVSS 4.3EG 4.32026-07-16
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoint…
- CVE-2026-5730HIGHCVSS 7.5EG 7.52026-07-07
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
- CVE-2026-57341MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
- CVE-2026-57494HIGHCVSS 7.1EG 7.12026-06-18
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target a…
- CVE-2026-57498CRITICALCVSS 9.6EG 9.62026-06-29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any oper…
- CVE-2026-5750HIGHCVSS 7.6EG 7.62026-04-22
An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging to other registered users through various vulnerable authenticated resources in the applic…
- CVE-2026-57630MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
- CVE-2026-57634MEDIUMCVSS 4.3EG 4.32026-06-26
Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.
- CVE-2026-57646MEDIUMCVSS 5.4EG 5.42026-06-26
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
- CVE-2026-57652MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
- CVE-2026-57665MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
- CVE-2026-57676MEDIUMCVSS 4.3EG 4.32026-06-29
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
- CVE-2026-57680MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
- CVE-2026-57694MEDIUMCVSS 6.5EG 6.52026-07-13
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.
- CVE-2026-57868HIGHCVSS 7.1EG 7.12026-07-07
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57869HIGHCVSS 7.1EG 7.12026-07-07
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects Micr…
- CVE-2026-57870MEDIUMCVSS 5.3EG 5.32026-07-07
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57943MEDIUMCVSS 5.9EG 5.92026-06-29
LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation…
- CVE-2026-57945MEDIUMCVSS 4.3EG 4.32026-06-29
PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit t…
- CVE-2026-57956MEDIUMCVSS 6.4EG 6.42026-06-29
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organizat…
- CVE-2026-5798HIGHCVSS 7.1EG 7.12026-05-14
Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulner…
- CVE-2026-5799HIGHCVSS 7.5EG 7.52026-07-07
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
- CVE-2026-58410HIGHCVSS 7.1EG 7.12026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated …
- CVE-2026-5842HIGHCVSS 7.3EG 7.32026-04-09
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The atta…
- CVE-2026-58447MEDIUMCVSS 6.5EG 6.52026-06-30
Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video ind…
- CVE-2026-5845CRITICALCVSS 9.6EG 9.62026-04-21
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can incl…
- CVE-2026-58580MEDIUMCVSS 5.9EG 5.92026-07-02
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows…
- CVE-2026-58653MEDIUMCVSS 4.3EG 4.32026-07-02
PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution …
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →