CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,706 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 49 of 55
- CVE-2026-74242MEDIUMCVSS 4.4EG 5.32026-08-14
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook UR…
- CVE-2026-74771MEDIUMCVSS 6.5EG 6.52026-08-26
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Informatio…
- CVE-2026-74877HIGHCVSS 8.8EG 8.82026-08-17
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a va…
- CVE-2026-7491HIGHCVSS 8.1EG 8.12026-05-02
School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data.
- CVE-2026-74930MEDIUMCVSS 4.3EG 4.32026-08-26
The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read a…
- CVE-2026-7502MEDIUMCVSS 5.4EG 5.42026-04-30
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation lead…
- CVE-2026-75033HIGHCVSS 7.7EG 7.72026-09-03
A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user a…
- CVE-2026-75035MEDIUMCVSS 6.5EG 6.52026-09-03
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authentic…
- CVE-2026-7510MEDIUMCVSS 6.3EG 6.32026-04-30
A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulation can lead to authorization bypass. The…
- CVE-2026-75103HIGHCVSS 8.8EG 8.82026-08-17
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and cha…
- CVE-2026-75105HIGHCVSS 7.5EG 7.52026-08-17
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId para…
- CVE-2026-75415HIGHCVSS 7.5EG 7.52026-08-26
AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identit…
- CVE-2026-75458HIGHCVSS 8.1EG 8.12026-08-31
The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted…
- CVE-2026-75460MEDIUMCVSS 6.5EG 6.52026-08-31
XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.
- CVE-2026-7573HIGHCVSS 7.7EG 7.72026-05-06
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user acr…
- CVE-2026-75950MEDIUMCVSS 6.9EG 6.92026-08-19
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3…
- CVE-2026-75951MEDIUMCVSS 6.9EG 6.92026-08-19
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
- CVE-2026-76073HIGHCVSS 8.8EG 8.82026-08-24
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default…
- CVE-2026-76216HIGHCVSS 7.5EG 7.52026-08-19
Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share JW…
- CVE-2026-76236HIGHCVSS 7.2EG 7.22026-08-19
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, a…
- CVE-2026-76237HIGHCVSS 8.6EG 8.62026-08-19
stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count quer…
- CVE-2026-76263MEDIUMCVSS 5.4EG 5.42026-08-19
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orche…
- CVE-2026-7638MEDIUMCVSS 5.3EG 5.32026-05-02
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `u…
- CVE-2026-76397HIGHCVSS 8.1EG 8.12026-08-19
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk A…
- CVE-2026-7648MEDIUMCVSS 4.3EG 4.32026-05-14
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. This is due to improper handling of us…
- CVE-2026-7651MEDIUMCVSS 5.3EG 5.32026-05-28
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio…
- CVE-2026-76634MEDIUMCVSS 6.5EG 6.52026-08-20
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extra…
- CVE-2026-76647HIGHCVSS 8.8EG 8.82026-08-19
Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer me…
- CVE-2026-7665MEDIUMCVSS 5.3EG 5.32026-06-06
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restric…
- CVE-2026-7681MEDIUMCVSS 6.5EG 6.52026-05-03
A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the file backend/webserver/api/datasets.py of the component Dataset API. The manipulation of t…
- CVE-2026-76901MEDIUMCVSS 5.8EG 5.82026-09-18
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.get…
- CVE-2026-7702MEDIUMCVSS 5.3EG 5.32026-05-03
A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId/:docId of the component Public Markdown Preview Endpoint. The manipulation results in aut…
- CVE-2026-77035MEDIUMCVSS 5.1EG 5.12026-08-27
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST anothe…
- CVE-2026-77073MEDIUMCVSS 4.3EG 4.32026-08-20
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID…
- CVE-2026-77079HIGHCVSS 8.8EG 8.82026-08-20
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and…
- CVE-2026-77081HIGHCVSS 7.1EG 7.12026-08-20
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is trea…
- CVE-2026-77116MEDIUMCVSS 4.3EG 4.32026-08-23
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by pass…
- CVE-2026-77127MEDIUMCVSS 6.0EG 6.02026-08-25
The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and t…
- CVE-2026-77135HIGHCVSS 8.2EG 8.22026-08-25
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, inclu…
- CVE-2026-77140HIGHCVSS 8.7EG 8.72026-08-25
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send…
- CVE-2026-77141HIGHCVSS 8.8EG 8.82026-08-25
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a clu…
- CVE-2026-77142HIGHCVSS 8.8EG 8.82026-08-25
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on th…
- CVE-2026-77143HIGHCVSS 8.8EG 8.82026-08-25
The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update req…
- CVE-2026-77145HIGHCVSS 7.1EG 7.12026-08-25
The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.
- CVE-2026-77240CRITICALCVSS 9.9EG 9.92026-09-18
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and…
- CVE-2026-77368HIGHCVSS 7.6EG 7.62026-08-26
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tena…
- CVE-2026-77385MEDIUMCVSS 4.3EG 4.32026-09-18
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/a…
- CVE-2026-77705HIGHCVSS 7.2EG 7.22026-09-12
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's …
- CVE-2026-77759HIGHCVSS 8.7EG 8.72026-08-21
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identi…
- CVE-2026-77764MEDIUMCVSS 4.3EG 4.32026-09-02
The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitr…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →