VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 105 of 115
  • CVE-2026-13116MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-55881HigJul 10, 2026
    risk 0.00cvss epss 0.00

    OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checked only that the project…

  • CVE-2026-55880HigJul 10, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while…

  • CVE-2026-55515MedJul 10, 2026
    risk 0.00cvss 5.0epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,…

  • CVE-2026-6212HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026.

  • CVE-2026-61460HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users.…

  • CVE-2026-55516HigJul 10, 2026
    risk 0.00cvss 7.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id without re-authorizing the newly supplied…

  • CVE-2026-55478MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a…

  • CVE-2026-59190HigJul 10, 2026
    risk 0.00cvss epss 0.00

    grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the super administrator, by sending…

  • CVE-2026-2398HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2026-56765CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.00

    Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task…

  • CVE-2026-41878HigJul 10, 2026
    risk 0.00cvss epss 0.00

    R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from the database by ID and serves them to whoever requests them, relying only on session authentication, meaning any valid user can…

  • CVE-2026-6802MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any…

  • CVE-2026-12400MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. This makes it possible for authenticated…

  • CVE-2026-55604HigJul 9, 2026
    risk 0.00cvss 8.6epss 0.00

    DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can…

  • CVE-2026-51925HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.00

    A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive…

  • CVE-2026-51924HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.00

    An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component

  • CVE-2026-51923HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.

  • CVE-2026-15191MedJul 9, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can lead to authorization…

  • CVE-2026-1989HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects PAVO Pay: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not…