CWE-639
Authorization Bypass Through User-Controlled Key
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Hierarchy (View 1000)
CVEs mapped to this weakness (2,283)
page 101 of 115| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-15630 | Cri | 0.00 | 9.9 | 0.00 | Jul 23, 2026 | A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body). | ||
| CVE-2026-65699 | Med | 0.00 | 4.2 | 0.00 | Jul 23, 2026 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The… | ||
| CVE-2026-47755 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the… | ||
| CVE-2026-65696 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters.… | ||
| CVE-2026-65917 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access… | ||
| CVE-2026-65501 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. | ||
| CVE-2026-65463 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | ||
| CVE-2026-65456 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. | ||
| CVE-2026-61946 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. | ||
| CVE-2026-16624 | Cri | 0.00 | 9.6 | 0.00 | Jul 22, 2026 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally… | ||
| CVE-2026-65013 | Hig | 0.00 | 8.8 | 0.00 | Jul 22, 2026 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get,… | ||
| CVE-2026-65016 | Hig | 0.00 | 8.8 | 0.00 | Jul 22, 2026 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role… | ||
| CVE-2026-63259 | Med | 0.00 | 4.3 | 0.00 | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. | ||
| CVE-2026-65316 | Med | 0.00 | 6.5 | 0.00 | Jul 21, 2026 | XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can… | ||
| CVE-2026-61064 | Med | 0.00 | 5.4 | 0.00 | Jul 21, 2026 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | ||
| CVE-2026-15342 | Med | 0.00 | 6.5 | 0.00 | Jul 21, 2026 | Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected… | ||
| CVE-2026-28317 | Cri | 0.00 | 9.1 | 0.00 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. | ||
| CVE-2026-28316 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The… | ||
| CVE-2026-28314 | Cri | 0.00 | 9.1 | 0.00 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. | ||
| CVE-2026-28313 | Cri | 0.00 | 9.1 | 0.00 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. |
- risk 0.00cvss 9.9epss 0.00
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
- risk 0.00cvss 4.2epss 0.00
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The…
- risk 0.00cvss 6.5epss 0.00
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the…
- risk 0.00cvss 5.4epss 0.00
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters.…
- risk 0.00cvss 8.8epss 0.00
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access…
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
- risk 0.00cvss 9.6epss 0.00
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally…
- risk 0.00cvss 8.8epss 0.00
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get,…
- risk 0.00cvss 8.8epss 0.00
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role…
- risk 0.00cvss 4.3epss 0.00
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
- risk 0.00cvss 6.5epss 0.00
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can…
- risk 0.00cvss 5.4epss 0.00
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
- risk 0.00cvss 6.5epss 0.00
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected…
- risk 0.00cvss 9.1epss 0.00
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The…
- risk 0.00cvss 9.1epss 0.00
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.00
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.