CWE-639
Authorization Bypass Through User-Controlled Key
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Hierarchy (View 1000)
CVEs mapped to this weakness (2,759)
page 134 of 138| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-56781 | Med | 0.00 | 5.3 | 0.00 | Jun 29, 2026 | Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the share view records endpoint. Attackers can enumerate hidden… | ||
| CVE-2026-56780 | Hig | 0.00 | 7.5 | 0.00 | Jun 29, 2026 | Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to… | ||
| CVE-2026-57341 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. | ||
| CVE-2026-57676 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9. | ||
| CVE-2026-13549 | Med | 0.00 | 5.4 | 0.01 | Jun 29, 2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can… | ||
| CVE-2026-13534 | Med | 0.00 | 5.0 | 0.00 | Jun 29, 2026 | A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The… | ||
| CVE-2026-13512 | Med | 0.00 | 6.3 | 0.00 | Jun 28, 2026 | A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulation leads to… | ||
| CVE-2026-13490 | Low | 0.00 | 3.7 | 0.00 | Jun 28, 2026 | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The… | ||
| CVE-2026-11987 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user… | ||
| CVE-2026-52782 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources.… | ||
| CVE-2026-52779 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion in the Calendar and Team Planner modules allows a user with management permissions in one project to delete public Calendar or… | ||
| CVE-2026-49355 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/inaccessible project. This vulnerability… | ||
| CVE-2026-44736 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary… | ||
| CVE-2026-44732 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update,… | ||
| CVE-2026-44731 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all… | ||
| CVE-2026-56823 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the… | ||
| CVE-2026-57665 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. | ||
| CVE-2026-57652 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | ||
| CVE-2026-57646 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions. | ||
| CVE-2026-57634 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions. |
- risk 0.00cvss 5.3epss 0.00
Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the share view records endpoint. Attackers can enumerate hidden…
- risk 0.00cvss 7.5epss 0.00
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to…
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
- risk 0.00cvss 4.3epss 0.00
Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.
- risk 0.00cvss 5.4epss 0.01
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can…
- risk 0.00cvss 5.0epss 0.00
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulation leads to…
- risk 0.00cvss 3.7epss 0.00
A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The…
- risk 0.00cvss 4.3epss 0.00
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user…
- risk 0.00cvss 9.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources.…
- risk 0.00cvss 5.4epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion in the Calendar and Team Planner modules allows a user with management permissions in one project to delete public Calendar or…
- risk 0.00cvss 4.3epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/inaccessible project. This vulnerability…
- risk 0.00cvss 6.5epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary…
- risk 0.00cvss 4.3epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update,…
- risk 0.00cvss 4.3epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all…
- risk 0.00cvss 5.4epss 0.00
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the…
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.