VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,730)

page 131 of 137
  • CVE-2026-58447MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the…

  • CVE-2026-27956MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/servers/{server_uuid}/domains?uuid={app_uuid}` bypasses team scoping when the optional uuid query parameter is provided. Any authenticated…

  • CVE-2026-27883MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any team, bypassing team-based…

  • CVE-2026-27881MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments/{uuid}` in DeployController.php retrieves deployment details without validating that the deployment belongs to the authenticated…

  • CVE-2026-12073CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't…

  • CVE-2026-34592HigJun 29, 2026
    risk 0.00cvss 7.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and project lookups are not scoped to the current team, allowing any authenticated user to access servers and projects belonging to other…

  • CVE-2026-57498CriJun 29, 2026
    risk 0.00cvss 9.6epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI…

  • CVE-2026-57956MedJun 29, 2026
    risk 0.00cvss 6.4epss 0.00

    SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and…

  • CVE-2026-57945MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier…

  • CVE-2026-57943MedJun 29, 2026
    risk 0.00cvss 5.9epss 0.00

    LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to…

  • CVE-2026-56781MedJun 29, 2026
    risk 0.00cvss 5.3epss 0.00

    Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the share view records endpoint. Attackers can enumerate hidden…

  • CVE-2026-56780HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to…

  • CVE-2026-57341MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.

  • CVE-2026-57676MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.

  • CVE-2026-13549MedJun 29, 2026
    risk 0.00cvss 5.4epss 0.01

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can…

  • CVE-2026-13534MedJun 29, 2026
    risk 0.00cvss 5.0epss 0.00

    A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The…

  • CVE-2026-13512MedJun 28, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulation leads to…

  • CVE-2026-13490LowJun 28, 2026
    risk 0.00cvss 3.7epss 0.00

    A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The…

  • CVE-2026-11987MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user…

  • CVE-2026-52782CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources.…