VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 129 of 138
  • CVE-2026-35147HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform…

  • CVE-2026-12906LowJul 16, 2026
    risk 0.00cvss 2.7epss 0.00

    The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending,…

  • CVE-2026-12510MedJul 16, 2026
    risk 0.00cvss 5.9epss 0.00

    The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when…

  • CVE-2026-15909MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out…

  • CVE-2026-55234HigJul 15, 2026
    risk 0.00cvss 8.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update…

  • CVE-2026-53447MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any…

  • CVE-2026-54052CriJul 15, 2026
    risk 0.00cvss 9.9epss 0.00

    n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per…

  • CVE-2026-48799HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account…

  • CVE-2026-44986CriJul 15, 2026
    risk 0.00cvss 9.9epss 0.01

    Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile…

  • CVE-2026-59259MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions…

  • CVE-2026-59254MedJul 15, 2026
    risk 0.00cvss —epss 0.00

    n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node…

  • CVE-2026-59236MedJul 15, 2026
    risk 0.00cvss —epss 0.01

    Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records…

  • CVE-2026-59235HigJul 15, 2026
    risk 0.00cvss —epss 0.01

    Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role (e.g. the…

  • CVE-2026-11580MedJul 15, 2026
    risk 0.00cvss 5.5epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type,…

  • CVE-2026-15637HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the …

  • CVE-2026-15058LowJul 14, 2026
    risk 0.00cvss 3.1epss 0.00

    Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

  • CVE-2026-9341MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and 'complete_lesson_video' AJAX handlers…

  • CVE-2026-15389HigJul 14, 2026
    risk 0.00cvss —epss 0.00

    A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST v3 API. The flaw lies in the fact that the system uses the session identifier (USID) as the sole validation mechanism, without…

  • CVE-2026-15622MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack…

  • CVE-2026-58410HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated non-admin user with EditSelf access can…