VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 100 of 115
  • CVE-2025-60931HigJul 29, 2026
    risk 0.00cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.

  • CVE-2026-5060MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the…

  • CVE-2026-63242MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records.

  • CVE-2026-63241LowJul 29, 2026
    risk 0.00cvss 3.1epss 0.00

    An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.

  • CVE-2026-57510HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas…

  • CVE-2026-49258HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not…

  • CVE-2026-18028LowJul 28, 2026
    risk 0.00cvss epss 0.00

    The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker could…

  • CVE-2026-16797MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key.…

  • CVE-2026-59240MedJul 27, 2026
    risk 0.00cvss epss 0.00

    The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authenticated user, regardless of company or permissions, to delete notifications…

  • CVE-2026-48052MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags belonging to a different organization, given the target tag's ID. The route handler verifies the…

  • CVE-2026-17570MedJul 27, 2026
    risk 0.00cvss 4.3epss 0.00

    Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * …

  • CVE-2026-17531MedJul 27, 2026
    risk 0.00cvss 5.0epss 0.00

    A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the…

  • CVE-2026-59546HigJul 27, 2026
    risk 0.00cvss 7.4epss 0.00

    Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

  • CVE-2026-59539HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

  • CVE-2026-66412MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can…

  • CVE-2026-66013CriJul 25, 2026
    risk 0.00cvss epss 0.00

    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console…

  • CVE-2026-65710HigJul 24, 2026
    risk 0.00cvss 7.1epss 0.00

    sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl…

  • CVE-2026-65709HigJul 24, 2026
    risk 0.00cvss 8.3epss 0.00

    sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control.…

  • CVE-2026-65708HigJul 24, 2026
    risk 0.00cvss 8.1epss 0.00

    sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in…

  • CVE-2026-13464MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it…