VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 70 of 115
  • CVE-2025-43724MedOct 8, 2025
    risk 0.29cvss 4.4epss 0.00

    Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares.

  • CVE-2025-2301MedJul 21, 2025
    risk 0.29cvss 4.4epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers. This issue affects Online Exam Registration: before 14.03.2025.

  • CVE-2025-47226MedMay 2, 2025
    risk 0.29cvss 5.0epss 0.01

    Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

  • CVE-2024-5258MedMay 23, 2024
    risk 0.29cvss 4.4epss 0.00

    An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

  • CVE-2024-22455MedFeb 14, 2024
    risk 0.29cvss 4.4epss 0.00

    Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Launch of phishing attacks.

  • CVE-2020-4918MedJan 4, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.

  • CVE-2026-18962MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other…

  • CVE-2026-14858MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.

  • CVE-2026-19579MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side…

  • CVE-2026-72540MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access…

  • CVE-2026-66764MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality,…

  • CVE-2026-18200MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including…

  • CVE-2026-17020MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer…

  • CVE-2026-15214MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product,…

  • CVE-2026-19066MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely.

  • CVE-2026-19064MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.

  • CVE-2026-14306MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and…

  • CVE-2026-66692MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

  • CVE-2025-11850MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks. This allows a subject to be associated with an unintended local account if…

  • CVE-2026-14938MedAug 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages…