VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 102 of 115
  • CVE-2026-28308CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

  • CVE-2026-28305CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows…

  • CVE-2026-28302CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

  • CVE-2026-16450MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to…

  • CVE-2026-14184MedJul 21, 2026
    risk 0.00cvss 5.4epss 0.00

    The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson…

  • CVE-2026-14183MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

  • CVE-2026-57494HigJul 20, 2026
    risk 0.00cvss epss 0.00

    AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET…

  • CVE-2026-55544HigJul 20, 2026
    risk 0.00cvss 7.6epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that…

  • CVE-2026-47198HigJul 20, 2026
    risk 0.00cvss 8.5epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning…

  • CVE-2026-47130HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact and target update endpoints. The application fails to verify if the authenticated user…

  • CVE-2026-45295MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…

  • CVE-2026-63763HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the…

  • CVE-2026-63745MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by…

  • CVE-2026-63735HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in…

  • CVE-2026-16217MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization…

  • CVE-2026-16214MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is…

  • CVE-2026-16075MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulation of the argument Username causes…

  • CVE-2026-13445HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim…

  • CVE-2026-63307MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.queryExistent(id, ...) without an ownership check and returns the decrypted password field, allowing any…