VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 110 of 115
  • CVE-2026-56823MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the…

  • CVE-2026-57665MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.

  • CVE-2026-57652MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.

  • CVE-2026-57646MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

  • CVE-2026-57634MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

  • CVE-2026-57630MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.

  • CVE-2026-56069HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

  • CVE-2026-56048MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.

  • CVE-2026-54839HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.

  • CVE-2026-54826HigJun 26, 2026
    risk 0.00cvss 7.6epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

  • CVE-2025-66123MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

  • CVE-2026-56772MedJun 25, 2026
    risk 0.00cvss 4.3epss 0.00

    NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id…

  • CVE-2026-9799MedJun 25, 2026
    risk 0.00cvss 4.6epss 0.00

    A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain…

  • CVE-2026-55411MedJun 25, 2026
    risk 0.00cvss 6.8epss 0.00

    ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose…

  • CVE-2026-13350LowJun 25, 2026
    risk 0.00cvss epss 0.00

    Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

  • CVE-2026-56013MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

  • CVE-2026-5309MedJun 25, 2026
    risk 0.00cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy…

  • CVE-2026-55611NonJun 24, 2026
    risk 0.00cvss 0.0epss 0.00

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId scoping to the parsed-files read/delete paths was added. However, the POST…

  • CVE-2025-62180HigJun 23, 2026
    risk 0.00cvss epss 0.00

    Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.

  • CVE-2026-54683Jun 18, 2026
    risk 0.00cvss epss

    ## Summary A previous advisory (CVE-2026-49463 / GHSA-qpm9-h556-mwxm) reported that any logged-in user could download any document by its identifier, and stated this was fixed in 3.0.1. For the document-content part that fix was **incomplete**: documents remained downloadable…