VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,334)

page 18 of 117
  • CVE-2019-17574CriOct 14, 2019
    risk 0.53cvss 9.1epss 0.09

    An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of…

  • CVE-2019-12782HigJul 9, 2019
    risk 0.53cvss 8.1epss 0.01

    An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update…

  • CVE-2026-47156criJul 15, 2026
    risk 0.52cvss epss

    MantisBT 2.28.3 and earlier contains a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowing their username), including the administrator, without knowing the target's…

  • CVE-2026-57168criJun 19, 2026
    risk 0.52cvss epss

    ### Summary OpenRemote Manager is vulnerable to a cross-tenant Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint. An authenticated user in any realm can delete alarms belonging to other realms (tenants) by supplying arbitrary alarm IDs. The…

  • CVE-2026-42889CriMay 12, 2026
    risk 0.52cvss 9.1epss 0.00

    Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token query parameter were incorrectly treated…

  • CVE-2026-33297CriMar 23, 2026
    risk 0.52cvss 9.1epss 0.00

    WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password…

  • CVE-2026-20912CriJan 22, 2026
    risk 0.52cvss 9.1epss 0.00

    Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.

  • CVE-2026-20897CriJan 22, 2026
    risk 0.52cvss 9.1epss 0.00

    Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

  • CVE-2025-50849HigJul 31, 2025
    risk 0.52cvss 8.0epss 0.00

    CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a parameter (company_id) sent in the request. However, this operation is not properly validated on the server side. An…

  • CVE-2025-52446HigJul 25, 2025
    risk 0.52cvss 8.0epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1.3, before…

  • CVE-2025-25777HigApr 24, 2025
    risk 0.52cvss 8.0epss 0.00

    Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.

  • CVE-2025-27507CriMar 4, 2025
    risk 0.52cvss 9.0epss 0.01

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, without specific IAM roles, to modify…

  • CVE-2024-23112HigMar 12, 2024
    risk 0.52cvss 8.0epss 0.01

    An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may…

  • CVE-2024-27302CriMar 6, 2024
    risk 0.52cvss 9.1epss 0.01

    go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allowed in CORS policy. However, the `isOriginAllowed` uses `strings.HasSuffix` to check the origin, which leads to bypass via a…

  • CVE-2024-22206CriJan 12, 2024
    risk 0.52cvss 9.0epss 0.01

    Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.

  • CVE-2022-40319HigJan 17, 2023
    risk 0.52cvss 7.5epss 0.07

    The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.

  • CVE-2022-1996CriJun 8, 2022
    risk 0.52cvss 9.1epss 0.03

    Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

  • CVE-2022-1165CriApr 4, 2022
    risk 0.52cvss 9.1epss 0.02

    The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as…

  • CVE-2022-0686CriFeb 20, 2022
    risk 0.52cvss 9.1epss 0.02

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

  • CVE-2026-58650HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.