CWE-639
Authorization Bypass Through User-Controlled Key
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Hierarchy (View 1000)
CVEs mapped to this weakness (2,730)
page 132 of 137| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-52779 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion in the Calendar and Team Planner modules allows a user with management permissions in one project to delete public Calendar or… | ||
| CVE-2026-49355 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/inaccessible project. This vulnerability… | ||
| CVE-2026-44736 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary… | ||
| CVE-2026-44732 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update,… | ||
| CVE-2026-44731 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all… | ||
| CVE-2026-56823 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the… | ||
| CVE-2026-57665 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. | ||
| CVE-2026-57652 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | ||
| CVE-2026-57646 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions. | ||
| CVE-2026-57634 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions. | ||
| CVE-2026-57630 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions. | ||
| CVE-2026-56069 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions. | ||
| CVE-2026-56048 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. | ||
| CVE-2026-54839 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions. | ||
| CVE-2026-54826 | Hig | 0.00 | 7.6 | 0.00 | Jun 26, 2026 | Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions. | ||
| CVE-2025-66123 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions. | ||
| CVE-2026-56772 | Med | 0.00 | 4.3 | 0.00 | Jun 25, 2026 | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id… | ||
| CVE-2026-9799 | Med | 0.00 | 4.6 | 0.00 | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain… | ||
| CVE-2026-55411 | Med | 0.00 | 6.8 | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose… | ||
| CVE-2026-13350 | Low | 0.00 | — | 0.00 | Jun 25, 2026 | Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create. |
- risk 0.00cvss 5.4epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion in the Calendar and Team Planner modules allows a user with management permissions in one project to delete public Calendar or…
- risk 0.00cvss 4.3epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/inaccessible project. This vulnerability…
- risk 0.00cvss 6.5epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary…
- risk 0.00cvss 4.3epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update,…
- risk 0.00cvss 4.3epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all…
- risk 0.00cvss 5.4epss 0.00
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the…
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.
- risk 0.00cvss 7.6epss 0.00
Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
- risk 0.00cvss 4.3epss 0.00
NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id…
- risk 0.00cvss 4.6epss 0.00
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain…
- risk 0.00cvss 6.8epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose…
- risk 0.00cvss —epss 0.00
Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.