VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 123 of 138
  • CVE-2026-23522LowJan 19, 2026
    risk 0.17cvss 3.7epss 0.00

    LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filter in the database query is…

  • CVE-2024-1075LowFeb 5, 2024
    risk 0.17cvss 3.7epss 0.01

    The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for…

  • CVE-2023-38872LowSep 28, 2023
    risk 0.17cvss 3.7epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.

  • CVE-2026-86763LowSep 9, 2026
    risk 0.16cvss 3.5epss 0.00

    Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, while its files() and activeFile()…

  • CVE-2026-45159LowJun 1, 2026
    risk 0.16cvss 3.5epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files…

  • CVE-2024-12767LowMay 15, 2025
    risk 0.16cvss 3.5epss 0.00

    The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

  • CVE-2024-25983LowFeb 19, 2024
    risk 0.16cvss 3.5epss 0.01

    Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

  • CVE-2026-47388LowJun 23, 2026
    risk 0.15cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment path could read any file in shared storage, including attachments belonging to other bases and workspaces, because the MCP…

  • CVE-2026-84025LowSep 12, 2026
    risk 0.14cvss 2.2epss 0.00

    The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected…

  • CVE-2026-84225LowSep 5, 2026
    risk 0.14cvss 2.2epss 0.00

    The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including…

  • CVE-2026-14823LowAug 1, 2026
    risk 0.14cvss 2.2epss 0.00

    The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of…

  • CVE-2026-52839LowJul 14, 2026
    risk 0.14cvss 3.3epss 0.00

    Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints…

  • CVE-2025-12997LowDec 4, 2025
    risk 0.14cvss 2.2epss 0.00

    Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects…

  • CVE-2024-10452LowOct 29, 2024
    risk 0.14cvss 2.2epss 0.00

    Organization admins can delete pending invites created in an organization they are not part of.

  • CVE-2026-100534LowSep 26, 2026
    risk 0.13cvss 3.1epss 0.00

    OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work…

  • CVE-2026-84298LowSep 21, 2026
    risk 0.13cvss 3.1epss 0.00

    Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and…

  • CVE-2026-52841LowJul 14, 2026
    risk 0.13cvss 3.1epss 0.00

    Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row…

  • CVE-2026-59215LowJul 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message from another private or DM…

  • CVE-2026-47716LowMay 26, 2026
    risk 0.13cvss 3.1epss 0.00

    Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the requested bulk action to the submitted issue IDs without also requiring those issues to belong to that…

  • CVE-2026-47715LowMay 26, 2026
    risk 0.13cvss 3.1epss 0.00

    Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requiring it to belong to the issue in the URL. This is a project-boundary…