CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,706 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 53 of 55
- CVE-2026-86277HIGHCVSS 7.3EG 7.32026-09-07
A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass.…
- CVE-2026-8629HIGHCVSS 8.1EG 8.12026-05-14
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploi…
- CVE-2026-86408MEDIUMCVSS 6.5EG 6.52026-09-07
Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected…
- CVE-2026-86451MEDIUMCVSS 4.3EG 4.32026-09-07
Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object the reference belon…
- CVE-2026-86465MEDIUMCVSS 6.5EG 6.52026-09-16
Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator…
- CVE-2026-86481MEDIUMCVSS 4.3EG 4.32026-09-07
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
- CVE-2026-86488MEDIUMCVSS 6.5EG 6.52026-09-07
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
- CVE-2026-86489MEDIUMCVSS 6.5EG 6.52026-09-07
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
- CVE-2026-86720HIGHCVSS 8.1EG 8.12026-09-08
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. At…
- CVE-2026-86725HIGHCVSS 7.1EG 7.12026-09-08
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. A…
- CVE-2026-86743MEDIUMCVSS 5.0EG 5.02026-09-09
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report…
- CVE-2026-86761MEDIUMCVSS 4.3EG 4.32026-09-09
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned a…
- CVE-2026-86763LOWCVSS 3.5EG 3.52026-09-09
Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, w…
- CVE-2026-86782MEDIUMCVSS 5.5EG 5.52026-09-11
The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not…
- CVE-2026-8679HIGHCVSS 7.5EG 7.52026-05-22
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controll…
- CVE-2026-86840CRITICALCVSS 9.1EG 9.12026-09-08
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying th…
- CVE-2026-87019MEDIUMCVSS 4.3EG 4.32026-09-09
Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87025MEDIUMCVSS 5.4EG 5.42026-09-09
Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87033MEDIUMCVSS 5.4EG 5.42026-09-09
Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87047MEDIUMCVSS 6.3EG 6.32026-09-09
Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87113MEDIUMCVSS 6.3EG 6.32026-09-16
Tanium addressed an improper access controls vulnerability in Threat Response.
- CVE-2026-87809MEDIUMCVSS 6.5EG 6.52026-09-09
Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of pri…
- CVE-2026-87829MEDIUMCVSS 4.3EG 4.32026-09-17
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrar…
- CVE-2026-8786MEDIUMCVSS 6.3EG 6.32026-05-18
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation o…
- CVE-2026-87894MEDIUMCVSS 5.3EG 5.32026-09-12
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing u…
- CVE-2026-87966MEDIUMCVSS 5.3EG 5.32026-09-18
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id,…
- CVE-2026-87994MEDIUMCVSS 4.3EG 4.32026-09-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a su…
- CVE-2026-87997MEDIUMCVSS 4.3EG 4.32026-09-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id i…
- CVE-2026-88065HIGHCVSS 7.5EG 7.52026-09-15
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/phot…
- CVE-2026-8828HIGHCVSS 8.8EG 8.82026-06-12
A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong t…
- CVE-2026-8839MEDIUMCVSS 5.3EG 5.32026-06-06
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes regis…
- CVE-2026-88844LOWCVSS 2.7EG 2.72026-09-18
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress p…
- CVE-2026-88865HIGHCVSS 8.1EG 8.12026-09-10
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can excha…
- CVE-2026-88877CRITICALCVSS 9.8EG 9.82026-09-10
Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-ww…
- CVE-2026-8890HIGHCVSS 8.2EG 8.22026-05-26
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP header. The middleware in middleware.ts ski…
- CVE-2026-88910MEDIUMCVSS 5.3EG 5.32026-09-16
The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.
- CVE-2026-88912MEDIUMCVSS 4.2EG 4.22026-09-13
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, al…
- CVE-2026-89029MEDIUMCVSS 4.3EG 4.32026-09-16
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner…
- CVE-2026-89031MEDIUMCVSS 5.4EG 5.42026-09-16
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts…
- CVE-2026-89063HIGHCVSS 7.5EG 7.52026-09-16
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…
- CVE-2026-89141MEDIUMCVSS 6.5EG 6.52026-09-15
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a u…
- CVE-2026-89252MEDIUMCVSS 6.5EG 6.52026-09-11
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's L…
- CVE-2026-89257MEDIUMCVSS 5.4EG 5.42026-09-11
AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the at…
- CVE-2026-89262HIGHCVSS 7.5EG 7.52026-09-11
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments…
- CVE-2026-89264MEDIUMCVSS 4.3EG 4.32026-09-11
MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the requ…
- CVE-2026-89333MEDIUMCVSS 6.5EG 6.52026-09-19
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…
- CVE-2026-90517MEDIUMCVSS 5.3EG 5.32026-09-13
A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may …
- CVE-2026-90521MEDIUMCVSS 6.3EG 6.32026-09-13
A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulat…
- CVE-2026-90534MEDIUMCVSS 6.5EG 6.52026-09-12
Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods wit…
- CVE-2026-90542MEDIUMCVSS 5.4EG 5.42026-09-12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders fo…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →