VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 51 of 115
  • CVE-2020-13462MedFeb 9, 2021
    risk 0.37cvss 5.7epss 0.00

    Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.

  • CVE-2017-0936MedMar 28, 2018
    risk 0.37cvss 5.7epss 0.01

    Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither…

  • CVE-2026-32694MedMar 18, 2026
    risk 0.36cvss 6.6epss 0.00

    In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious grantee which can request secrets to predict past…

  • CVE-2025-8884MedOct 20, 2025
    risk 0.36cvss 5.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.

  • CVE-2025-59562MedSep 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.3.4.

  • CVE-2024-13175MedJul 18, 2025
    risk 0.36cvss 5.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. This issue affects VOC TESTER: before 12.41.0.

  • CVE-2025-24976MedFeb 11, 2025
    risk 0.36cvss epss 0.00

    Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an…

  • CVE-2022-48505MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system

  • CVE-2023-32352MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may bypass Gatekeeper checks.

  • CVE-2022-23173MedJul 6, 2022
    risk 0.36cvss 5.5epss 0.01

    this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the…

  • CVE-2022-0266MedJan 19, 2022
    risk 0.36cvss 6.6epss 0.01

    Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.

  • CVE-2021-31970MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    Windows TCP/IP Driver Security Feature Bypass Vulnerability

  • CVE-2021-26024MedFeb 3, 2021
    risk 0.36cvss 5.3epss 0.19

    The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.

  • CVE-2020-26068MedNov 18, 2020
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could…

  • CVE-2026-58435MedAug 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Gitea LFS Deploy-Key Privilege Escalation

  • CVE-2026-68076MedAug 12, 2026
    risk 0.35cvss 5.4epss 0.00

    Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which…

  • CVE-2026-47230MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the cross-folder move bug (`05-documents-cross-folder-move-idor.md`): the top-level rights check at lines 79-89…

  • CVE-2026-47227MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific category editable by me" check at lines 56-61…

  • CVE-2026-47226MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they have only view access. The authorization check at the top of…

  • CVE-2026-69117MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH…