CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,116 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 21 of 43
- CVE-2025-2301MEDIUMCVSS 4.4EG 4.42025-07-21
Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers. This issue affects Online Exam Registration: before 14.03.2025.
- CVE-2025-24315MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
- CVE-2025-24487MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
- CVE-2025-24850MEDIUMCVSS 5.3EG 5.32025-04-15
An attacker can export other users' plant information.
- CVE-2025-24969MEDIUMCVSS 5.0EG 5.02025-05-14
iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.
- CVE-2025-24976MEDIUMCVSS 6.6EG 6.62025-02-11
Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication …
- CVE-2025-2526HIGHCVSS 8.8EG 8.82025-04-08
The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details li…
- CVE-2025-25276MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can hijack other users' devices and potentially control them.
- CVE-2025-25282HIGHCVSS 8.1EG 8.12025-02-21
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-ten…
- CVE-2025-25777HIGHCVSS 8.0EG 8.02025-04-24
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentic…
- CVE-2025-25952MEDIUMCVSS 6.5EG 6.52025-03-03
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user informati…
- CVE-2025-26660MEDIUMCVSS 4.3EG 4.32025-03-11
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass ac…
- CVE-2025-26788HIGHCVSS 8.4EG 8.42025-02-14
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
- CVE-2025-26857MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
- CVE-2025-26965MEDIUMCVSS 5.3EG 5.32025-02-25
Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.16.
- CVE-2025-26977LOWCVSS 3.8EG 3.82025-02-25
Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through <= 6.4.2.1.
- CVE-2025-27433MEDIUMCVSS 4.3EG 4.32025-03-11
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of the application and upload files to a reversed bank statement. This vulnerability has a low impact on the application's…
- CVE-2025-27436MEDIUMCVSS 4.3EG 4.32025-03-11
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to confirm whether a request to interact with a resource is legitimate, allowing the attacker to delete the attachment of a…
- CVE-2025-27507CRITICALCVSS 9.0EG 9.02025-03-04
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, with…
- CVE-2025-27561MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can rename "rooms" of arbitrary users.
- CVE-2025-27565MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.
- CVE-2025-27568MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
- CVE-2025-27575MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.
- CVE-2025-27719MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can query an API endpoint and get device details.
- CVE-2025-27927MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
- CVE-2025-27929MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.
- CVE-2025-27938MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
- CVE-2025-27939HIGHCVSS 7.5EG 7.52025-04-15
An attacker can change registered email addresses of other users and take over arbitrary accounts.
- CVE-2025-28874MEDIUMCVSS 6.5EG 6.52025-03-11
Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templa…
- CVE-2025-30254MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
- CVE-2025-30257MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.
- CVE-2025-30514MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
- CVE-2025-30777MEDIUMCVSS 4.3EG 4.32025-03-27
Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.1…
- CVE-2025-3089MEDIUMCVSS 5.3EG 5.32025-08-12
ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to bypass access controls and perform a limited set of actions typically…
- CVE-2025-3091HIGHCVSS 7.5EG 7.52025-06-24
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.
- CVE-2025-31147MEDIUMCVSS 5.3EG 5.32025-04-15
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
- CVE-2025-31357MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can obtain a user's plant list by knowing the username.
- CVE-2025-31360MEDIUMCVSS 6.5EG 6.52025-04-15
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
- CVE-2025-31654MEDIUMCVSS 5.3EG 5.32025-04-15
An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
- CVE-2025-31833MEDIUMCVSS 4.9EG 4.92025-04-01
Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a thro…
- CVE-2025-31867MEDIUMCVSS 5.4EG 5.42025-04-01
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through <= 2.0.2.
- CVE-2025-31933MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
- CVE-2025-31941MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
- CVE-2025-31945MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can obtain other users' charger information.
- CVE-2025-31949MEDIUMCVSS 5.3EG 5.32025-04-15
An authenticated attacker can obtain any plant name by knowing the plant ID.
- CVE-2025-31950MEDIUMCVSS 5.3EG 5.32025-04-15
An unauthenticated attacker can obtain EV charger energy consumption information of other users.
- CVE-2025-31997MEDIUMCVSS 4.2EG 4.22025-10-12
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
- CVE-2025-32223MEDIUMCVSS 6.5EG 6.52026-03-19
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.
- CVE-2025-32373MEDIUMCVSS 6.5EG 6.52025-04-09
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not …
- CVE-2025-32781MEDIUMCVSS 6.5EG 6.52026-07-13
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a re…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →