VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 130 of 138
  • CVE-2026-6541MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or…

  • CVE-2026-61971LowJul 13, 2026
    risk 0.00cvss 2.7epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.

  • CVE-2026-57694MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

  • CVE-2026-9708MedJul 13, 2026
    risk 0.00cvss 4.9epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages…

  • CVE-2026-14165HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.

  • CVE-2026-15516MedJul 13, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The…

  • CVE-2026-10041MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-13116MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-55881HigJul 10, 2026
    risk 0.00cvss —epss 0.00

    OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checked only that the project…

  • CVE-2026-55880HigJul 10, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while…

  • CVE-2026-6212HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026.

  • CVE-2026-61460HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.01

    Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users.…

  • CVE-2026-59190HigJul 10, 2026
    risk 0.00cvss —epss 0.00

    grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the super administrator, by sending…

  • CVE-2026-2398HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2026-56765CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.01

    Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task…

  • CVE-2026-41878HigJul 10, 2026
    risk 0.00cvss —epss 0.00

    R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from the database by ID and serves them to whoever requests them, relying only on session authentication, meaning any valid user can…

  • CVE-2026-6802MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any…

  • CVE-2026-12400MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. This makes it possible for authenticated…

  • CVE-2026-51925HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.01

    A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive…

  • CVE-2026-51924HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.01

    An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component