CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,706 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 52 of 55
- CVE-2026-83711CRITICALCVSS 10.0EG 10.02026-09-03
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-83743MEDIUMCVSS 6.3EG 6.32026-09-01
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can…
- CVE-2026-84025LOWCVSS 2.2EG 2.22026-09-12
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product inf…
- CVE-2026-8406HIGHCVSS 7.1EG 7.12026-06-11
openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supp…
- CVE-2026-84062MEDIUMCVSS 4.3EG 4.32026-09-10
BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused.
- CVE-2026-84148CRITICALCVSS 9.2EG 9.22026-09-01
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to ex…
- CVE-2026-84205MEDIUMCVSS 6.5EG 6.52026-09-01
GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same …
- CVE-2026-84225LOWCVSS 2.2EG 2.22026-09-05
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify…
- CVE-2026-84672HIGHCVSS 8.8EG 8.82026-09-02
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a col…
- CVE-2026-84769MEDIUMCVSS 6.5EG 6.52026-09-03
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
- CVE-2026-84771MEDIUMCVSS 5.3EG 5.32026-09-02
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
- CVE-2026-84796HIGHCVSS 8.8EG 8.82026-09-02
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, mo…
- CVE-2026-84836HIGHCVSS 7.1EG 7.12026-09-03
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
- CVE-2026-84860HIGHCVSS 8.8EG 8.82026-09-16
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-meth…
- CVE-2026-85009MEDIUMCVSS 6.5EG 6.52026-09-18
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable …
- CVE-2026-85037MEDIUMCVSS 5.3EG 5.32026-09-09
The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price d…
- CVE-2026-85105HIGHCVSS 7.3EG 7.32026-09-03
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass…
- CVE-2026-85173MEDIUMCVSS 4.3EG 4.32026-09-03
n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attacke…
- CVE-2026-85177MEDIUMCVSS 5.4EG 5.42026-09-03
CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns includin…
- CVE-2026-85178HIGHCVSS 7.7EG 7.72026-09-03
Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner …
- CVE-2026-85182HIGHCVSS 7.5EG 7.52026-09-03
vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's…
- CVE-2026-85211HIGHCVSS 7.7EG 7.72026-09-03
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbi…
- CVE-2026-85214HIGHCVSS 8.1EG 8.12026-09-03
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and…
- CVE-2026-85308MEDIUMCVSS 5.3EG 5.32026-09-03
Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.
- CVE-2026-85378HIGHCVSS 7.3EG 7.32026-09-03
A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterC…
- CVE-2026-85381MEDIUMCVSS 5.3EG 5.32026-09-04
A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.cla…
- CVE-2026-85389MEDIUMCVSS 6.5EG 6.52026-09-03
Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUIDs …
- CVE-2026-85392MEDIUMCVSS 4.3EG 4.32026-09-03
Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs. Attackers can for…
- CVE-2026-85579MEDIUMCVSS 4.3EG 4.32026-09-04
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-…
- CVE-2026-85594CRITICALCVSS 9.8EG 9.82026-09-04
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the …
- CVE-2026-85607HIGHCVSS 8.8EG 8.82026-09-04
Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/route…
- CVE-2026-85611MEDIUMCVSS 6.4EG 6.42026-09-04
OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated atta…
- CVE-2026-85615MEDIUMCVSS 6.4EG 6.42026-09-04
Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply…
- CVE-2026-85616HIGHCVSS 8.5EG 8.52026-09-04
Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acc…
- CVE-2026-85617HIGHCVSS 8.8EG 8.82026-09-04
snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in …
- CVE-2026-85624MEDIUMCVSS 6.5EG 6.52026-09-04
Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and…
- CVE-2026-85638HIGHCVSS 7.3EG 7.32026-09-04
A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has…
- CVE-2026-85693MEDIUMCVSS 6.5EG 6.52026-09-04
Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-…
- CVE-2026-8611MEDIUMCVSS 4.3EG 4.32026-06-06
The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.4 via the 'invoice_id' parameter due to missing validation on a user controlled key. This mak…
- CVE-2026-86111MEDIUMCVSS 6.5EG 6.52026-09-05
BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access…
- CVE-2026-86112MEDIUMCVSS 5.4EG 5.42026-09-05
BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST…
- CVE-2026-86113MEDIUMCVSS 6.5EG 6.52026-09-05
BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite ar…
- CVE-2026-86174MEDIUMCVSS 4.3EG 4.32026-09-05
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to th…
- CVE-2026-86176MEDIUMCVSS 4.3EG 4.32026-09-05
NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through un…
- CVE-2026-86183MEDIUMCVSS 5.3EG 5.32026-09-06
A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argum…
- CVE-2026-86191MEDIUMCVSS 4.3EG 4.32026-09-05
SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibi…
- CVE-2026-86192MEDIUMCVSS 6.5EG 6.52026-09-05
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing priva…
- CVE-2026-86261HIGHCVSS 7.3EG 7.32026-09-07
A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order…
- CVE-2026-86262HIGHCVSS 7.3EG 7.32026-09-07
A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderContr…
- CVE-2026-86263HIGHCVSS 7.3EG 7.32026-09-07
A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the com…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →