VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 96 of 115
  • CVE-2025-8447LowAug 26, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker…

  • CVE-2025-24856MedMar 16, 2025
    risk 0.20cvss 4.2epss 0.00

    An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the following requirements are met: (1) an attacker…

  • CVE-2024-6685LowSep 16, 2024
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.

  • CVE-2024-39901MedJul 9, 2024
    risk 0.20cvss 4.2epss 0.00

    OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the…

  • CVE-2022-31027MedJun 9, 2022
    risk 0.20cvss 4.2epss 0.00

    OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The…

  • CVE-2020-26173LowDec 18, 2020
    risk 0.20cvss 3.1epss 0.01

    An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.

  • CVE-2026-52882medJul 15, 2026
    risk 0.19cvss epss

    ### Impact Users below _report_issues_for_unreleased_versions_threshold_ can assign unreleased product versions. ### Patches - https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f ### Workarounds None ### Resources -…

  • CVE-2026-55482medJun 23, 2026
    risk 0.19cvss epss

    ### Impact The `BulkAssetsController::update()` method accepts `company_id` directly from user input without calling `Company::getIdForCurrentUser()`, the standard company-scoping function used by every other controller in the codebase. A non-superadmin user can move assets…

  • CVE-2026-58445LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

  • CVE-2026-16957LowAug 9, 2026
    risk 0.18cvss 2.7epss 0.00

    The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published…

  • CVE-2026-16746LowAug 5, 2026
    risk 0.18cvss 2.7epss 0.00

    The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

  • CVE-2026-14195LowAug 1, 2026
    risk 0.18cvss 2.7epss 0.00

    The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft…

  • CVE-2026-9712LowMay 27, 2026
    risk 0.18cvss epss 0.00

    When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID…

  • CVE-2026-3307LowApr 21, 2026
    risk 0.18cvss 2.7epss 0.00

    An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter…

  • CVE-2026-6570LowApr 19, 2026
    risk 0.18cvss 2.7epss 0.00

    A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely.…

  • CVE-2026-39510LowApr 8, 2026
    risk 0.18cvss 2.7epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a…

  • CVE-2025-14882LowDec 19, 2025
    risk 0.18cvss epss 0.00

    An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

  • CVE-2025-14881LowDec 19, 2025
    risk 0.18cvss epss 0.00

    Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

  • CVE-2025-12954LowDec 3, 2025
    risk 0.18cvss 2.7epss 0.00

    The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.

  • CVE-2024-30507LowMar 29, 2024
    risk 0.18cvss 2.7epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.