VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 127 of 138
  • CVE-2026-15342MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected…

  • CVE-2026-28317CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.

  • CVE-2026-28316CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.02

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The…

  • CVE-2026-28314CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

  • CVE-2026-28313CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

  • CVE-2026-28308CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

  • CVE-2026-28305CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows…

  • CVE-2026-28302CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

  • CVE-2026-16450MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to…

  • CVE-2026-14184MedJul 21, 2026
    risk 0.00cvss 5.4epss 0.00

    The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson…

  • CVE-2026-14183MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

  • CVE-2026-57494HigJul 20, 2026
    risk 0.00cvss —epss 0.00

    AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET…

  • CVE-2026-55544HigJul 20, 2026
    risk 0.00cvss 7.6epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that…

  • CVE-2026-47198HigJul 20, 2026
    risk 0.00cvss 8.5epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning…

  • CVE-2026-47130HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact and target update endpoints. The application fails to verify if the authenticated user…

  • CVE-2026-45295MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss —epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…

  • CVE-2026-63763HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.01

    SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the…

  • CVE-2026-63745MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by…

  • CVE-2026-16217MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization…