VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 108 of 115
  • CVE-2026-58580MedJul 2, 2026
    risk 0.00cvss 5.9epss 0.00

    LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the…

  • CVE-2026-58653MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation…

  • CVE-2026-57680MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.

  • CVE-2026-9188MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointment `edit_key` — the sole authorization…

  • CVE-2026-12657MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_id' parameter due to missing validation on a user controlled key. This makes…

  • CVE-2026-11896MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 via the 'vcal' parameter due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-5348MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to the '/topics' REST API endpoint being registered with a permission callback set…

  • CVE-2026-49858MedJul 1, 2026
    risk 0.00cvss 5.9epss 0.00

    API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)]…

  • CVE-2026-5142MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data…

  • CVE-2026-5135MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes,…

  • CVE-2026-53903HigJul 1, 2026
    risk 0.00cvss 8.1epss 0.00

    MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement endpoint. The application does not properly validate whether an authenticated user is authorized to access a requested document,…

  • CVE-2026-10096MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level…

  • CVE-2026-12904MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in…

  • CVE-2026-11988MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This…

  • CVE-2026-56230HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-id header without validating ownership, allowing authenticated users to adopt cross-tenant limited keys. Attackers can supply…

  • CVE-2026-58447MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the…

  • CVE-2026-27956MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/servers/{server_uuid}/domains?uuid={app_uuid}` bypasses team scoping when the optional uuid query parameter is provided. Any authenticated…

  • CVE-2026-27883MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any team, bypassing team-based…

  • CVE-2026-27881MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments/{uuid}` in DeployController.php retrieves deployment details without validating that the deployment belongs to the authenticated…

  • CVE-2026-12073CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.00

    The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't…