CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,706 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 51 of 55
- CVE-2026-81210HIGHCVSS 7.7EG 7.72026-09-10
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained t…
- CVE-2026-81299MEDIUMCVSS 4.3EG 4.32026-08-28
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
- CVE-2026-81340LOWCVSS 3.8EG 3.82026-09-18
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the s…
- CVE-2026-81424MEDIUMCVSS 5.3EG 5.32026-09-05
The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at …
- CVE-2026-81428MEDIUMCVSS 6.5EG 6.52026-09-02
The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to o…
- CVE-2026-81505HIGHCVSS 7.1EG 7.12026-09-18
Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and…
- CVE-2026-8155MEDIUMCVSS 5.4EG 5.42026-07-31
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
- CVE-2026-81576HIGHCVSS 7.7EG 7.72026-08-27
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's hand…
- CVE-2026-81651LOWCVSS 3.1EG 3.12026-09-20
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settin…
- CVE-2026-81652LOWCVSS 2.7EG 2.72026-09-20
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the store…
- CVE-2026-81653MEDIUMCVSS 4.2EG 4.22026-09-20
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delet…
- CVE-2026-81654LOWCVSS 3.1EG 3.12026-09-20
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an admin…
- CVE-2026-81658MEDIUMCVSS 6.5EG 6.52026-08-27
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_pt…
- CVE-2026-81668MEDIUMCVSS 5.4EG 5.42026-08-27
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be a…
- CVE-2026-81802MEDIUMCVSS 6.5EG 6.52026-09-08
Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
- CVE-2026-81817HIGHCVSS 7.2EG 7.22026-08-27
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a case identifier and a task identifier, but previous…
- CVE-2026-81846LOWCVSS 3.5EG 3.52026-09-01
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/…
- CVE-2026-81853LOWCVSS 2.3EG 2.32026-08-31
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key f…
- CVE-2026-81892HIGHCVSS 8.1EG 8.12026-08-31
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem…
- CVE-2026-81915MEDIUMCVSS 5.1EG 5.12026-09-11
Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditP…
- CVE-2026-81916MEDIUMCVSS 4.3EG 4.32026-09-11
Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one…
- CVE-2026-8196LOWCVSS 3.7EG 3.72026-05-09
A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the component mLogin Endpoint.…
- CVE-2026-8204MEDIUMCVSS 5.3EG 5.32026-05-21
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. …
- CVE-2026-82125MEDIUMCVSS 5.3EG 5.32026-09-16
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of commen…
- CVE-2026-82213MEDIUMCVSS 5.3EG 5.32026-09-11
The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references…
- CVE-2026-82271MEDIUMCVSS 6.5EG 6.52026-08-28
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename c…
- CVE-2026-82280HIGHCVSS 7.1EG 7.12026-08-28
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite syst…
- CVE-2026-82281HIGHCVSS 7.4EG 7.42026-08-28
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversation…
- CVE-2026-82283HIGHCVSS 8.1EG 8.12026-08-28
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by sup…
- CVE-2026-82284HIGHCVSS 8.1EG 8.12026-08-28
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histo…
- CVE-2026-82290MEDIUMCVSS 5.3EG 5.32026-08-28
Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating da…
- CVE-2026-82305MEDIUMCVSS 5.3EG 5.32026-09-11
The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
- CVE-2026-82395MEDIUMCVSS 5.3EG 5.32026-08-31
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media it…
- CVE-2026-82441CRITICALCVSS 9.1EG 9.12026-09-14
Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the…
- CVE-2026-82564HIGHCVSS 7.1EG 7.12026-08-31
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Executio…
- CVE-2026-82582MEDIUMCVSS 4.3EG 4.32026-09-10
An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.
- CVE-2026-82602MEDIUMCVSS 5.3EG 5.32026-08-31
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been discl…
- CVE-2026-82621HIGHCVSS 7.3EG 7.32026-08-31
A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component A…
- CVE-2026-82685HIGHCVSS 7.6EG 7.62026-09-17
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token is…
- CVE-2026-82725LOWCVSS 2.3EG 2.32026-08-31
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows int…
- CVE-2026-82816MEDIUMCVSS 6.3EG 6.32026-08-31
A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. Th…
- CVE-2026-82851LOWCVSS 2.7EG 2.72026-09-12
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrar…
- CVE-2026-82869HIGHCVSS 7.7EG 7.72026-08-31
ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can re…
- CVE-2026-82870CRITICALCVSS 9.6EG 9.62026-08-31
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing orga…
- CVE-2026-82872CRITICALCVSS 9.1EG 9.12026-08-31
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another wor…
- CVE-2026-82873MEDIUMCVSS 5.0EG 5.02026-08-31
ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app defin…
- CVE-2026-82874CRITICALCVSS 9.9EG 9.92026-08-31
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tena…
- CVE-2026-82968MEDIUMCVSS 6.4EG 6.42026-09-02
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specifi…
- CVE-2026-8337MEDIUMCVSS 5.3EG 5.32026-05-21
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the …
- CVE-2026-8347MEDIUMCVSS 4.3EG 4.32026-05-26
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website ha…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →