CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,706 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 54 of 55
- CVE-2026-90552MEDIUMCVSS 4.3EG 4.32026-09-12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to rea…
- CVE-2026-90598MEDIUMCVSS 6.3EG 6.32026-09-13
A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipula…
- CVE-2026-90697MEDIUMCVSS 4.3EG 4.32026-09-14
A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attac…
- CVE-2026-90858HIGHCVSS 7.3EG 7.32026-09-15
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of th…
- CVE-2026-9087HIGHCVSS 8.1EG 8.12026-05-20
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it …
- CVE-2026-9099HIGHCVSS 7.7EG 7.72026-06-25
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Gr…
- CVE-2026-91008LOWCVSS 3.7EG 3.72026-09-17
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendee…
- CVE-2026-91016MEDIUMCVSS 5.3EG 5.32026-09-17
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car …
- CVE-2026-91144HIGHCVSS 7.5EG 7.52026-09-14
ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the s…
- CVE-2026-9130HIGHCVSS 7.1EG 7.12026-08-05
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_message…
- CVE-2026-9136MEDIUMCVSS 6.5EG 6.52026-05-20
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework…
- CVE-2026-9152CRITICALCVSS 10.0EG 10.02026-05-21
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of identity verification. An unauthenticate…
- CVE-2026-91770MEDIUMCVSS 6.5EG 6.52026-09-15
IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certi…
- CVE-2026-91773MEDIUMCVSS 4.3EG 4.32026-09-15
Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate…
- CVE-2026-9180MEDIUMCVSS 5.3EG 5.32026-07-03
The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoin…
- CVE-2026-91846HIGHCVSS 7.1EG 7.12026-09-15
Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves…
- CVE-2026-91847MEDIUMCVSS 4.8EG 4.82026-09-19
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticate…
- CVE-2026-9185HIGHCVSS 7.5EG 7.52026-06-09
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_pr…
- CVE-2026-9188MEDIUMCVSS 5.3EG 5.32026-07-02
The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointme…
- CVE-2026-91933HIGHCVSS 7.1EG 7.12026-09-15
Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can inv…
- CVE-2026-91984MEDIUMCVSS 4.3EG 4.32026-09-15
Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or …
- CVE-2026-91993MEDIUMCVSS 4.3EG 4.32026-09-15
Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifie…
- CVE-2026-9225MEDIUMCVSS 6.5EG 6.52026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v…
- CVE-2026-9228MEDIUMCVSS 4.3EG 4.32026-05-28
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled …
- CVE-2026-9241MEDIUMCVSS 4.3EG 4.32026-05-28
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `clas…
- CVE-2026-92420LOWCVSS 3.8EG 3.82026-09-19
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking…
- CVE-2026-92421MEDIUMCVSS 4.7EG 4.72026-09-19
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking …
- CVE-2026-92425MEDIUMCVSS 5.5EG 5.52026-09-19
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-as…
- CVE-2026-92468MEDIUMCVSS 6.5EG 6.52026-09-16
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{inde…
- CVE-2026-92469HIGHCVSS 8.1EG 8.12026-09-16
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers…
- CVE-2026-9248LOWCVSS 2.6EG 2.62026-05-26
Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save re…
- CVE-2026-92567MEDIUMCVSS 6.5EG 6.52026-09-16
TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submiss…
- CVE-2026-92577HIGHCVSS 7.5EG 7.52026-09-16
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by th…
- CVE-2026-92588MEDIUMCVSS 4.4EG 4.42026-09-16
n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of …
- CVE-2026-92603MEDIUMCVSS 6.5EG 6.52026-09-16
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message i…
- CVE-2026-92605MEDIUMCVSS 6.5EG 6.52026-09-16
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and rea…
- CVE-2026-92714MEDIUMCVSS 6.5EG 6.52026-09-18
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic '…
- CVE-2026-92716CRITICALCVSS 9.6EG 9.62026-09-16
Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with ad…
- CVE-2026-92752HIGHCVSS 8.3EG 8.32026-09-16
metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, a…
- CVE-2026-92765MEDIUMCVSS 6.5EG 6.52026-09-16
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to ret…
- CVE-2026-92773HIGHCVSS 7.1EG 7.12026-09-16
Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and suppl…
- CVE-2026-92809MEDIUMCVSS 4.3EG 4.32026-09-16
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for ot…
- CVE-2026-92810MEDIUMCVSS 4.3EG 4.32026-09-16
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential w…
- CVE-2026-9306LOWCVSS 3.7EG 3.72026-05-26
A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipula…
- CVE-2026-9341MEDIUMCVSS 4.3EG 4.32026-07-14
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and …
- CVE-2026-93660MEDIUMCVSS 6.5EG 6.52026-09-18
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to r…
- CVE-2026-93736MEDIUMCVSS 4.3EG 4.32026-09-18
Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can …
- CVE-2026-93758HIGHCVSS 8.1EG 8.12026-09-18
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a reques…
- CVE-2026-93955MEDIUMCVSS 4.3EG 4.32026-09-19
A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component D…
- CVE-2026-93991HIGHCVSS 7.7EG 7.72026-09-19
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Att…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →