VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 104 of 115
  • CVE-2026-48799HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account…

  • CVE-2026-44986CriJul 15, 2026
    risk 0.00cvss 9.9epss 0.00

    Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile…

  • CVE-2026-59259MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions…

  • CVE-2026-59254MedJul 15, 2026
    risk 0.00cvss epss 0.00

    n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node…

  • CVE-2026-59236MedJul 15, 2026
    risk 0.00cvss epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records…

  • CVE-2026-59235HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role (e.g. the…

  • CVE-2026-11580MedJul 15, 2026
    risk 0.00cvss 5.5epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type,…

  • CVE-2026-15637HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the …

  • CVE-2026-15058LowJul 14, 2026
    risk 0.00cvss 3.1epss 0.00

    Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

  • CVE-2026-9341MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and 'complete_lesson_video' AJAX handlers…

  • CVE-2026-15389HigJul 14, 2026
    risk 0.00cvss epss 0.00

    A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST v3 API. The flaw lies in the fact that the system uses the session identifier (USID) as the sole validation mechanism, without…

  • CVE-2026-15622MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack…

  • CVE-2026-58410HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated non-admin user with EditSelf access can…

  • CVE-2026-6541MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or…

  • CVE-2026-61971LowJul 13, 2026
    risk 0.00cvss 2.7epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.

  • CVE-2026-57694MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

  • CVE-2026-9708MedJul 13, 2026
    risk 0.00cvss 4.9epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages…

  • CVE-2026-14165HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.

  • CVE-2026-15516MedJul 13, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The…

  • CVE-2026-10041MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for…