CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,570 vulnerabilities with CWE-639
CVE-2026-7510 MEDIUM
OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization
CVSS 6.3
CVE-2026-6542 MEDIUM
Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id
CVSS 6.5
CVE-2026-7502 MEDIUM
LinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization
CVSS 5.4
CVE-2026-4503 HIGH
Unauthenticated Insecure Direct Object Reference (IDOR) Vulnerability in Langflow Desktop Image Download Endpoint
CVSS 7.5
CVE-2026-40600 HIGH
Chartbrew: Incorrect Access Control in project share policy routes via unbound policy_id
CVSS 8.1
CVE-2026-7399 HIGH
IDOR in MeWare Software's PDKS
CVSS 8.1
CVE-2026-42517 HIGH
Cryptographic Failure Vulnerability in e-Sushrut HMIS
CVE-2026-42516 HIGH
Broken Access Control Vulnerability in e-Sushrut HMIS
CVE-2026-42515 HIGH
Insecure Direct Object Reference (IDOR) Vulnerability in e-Sushrut HMIS
CVE-2026-41649 HIGH
Outline has IDOR in document share creation that allows unauthorized access to private documents across workspaces
CVSS 7.7
CVE-2026-41406 MEDIUM
OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted Messages
CVSS 5.4
CVE-2026-24178 CRITICAL
Nvidia Flare SDK - Authorization Bypass
CVSS 9.8
CVE-2026-41372 MEDIUM
OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery
CVSS 5.8
CVE-2026-28747 HIGH
Milesight Cameras Authorization Bypass Through User-Controlled Key
CVSS 7.1
CVE-2026-7145 MEDIUM
mettle sendportal Invitation WorkspaceInvitationsController.php destroy authorization
CVSS 5.4
CVE-2026-7144 MEDIUM
1000 Projects Portfolio Management System MCA update_passwd_process.php authorization
CVSS 4.3
CVE-2026-6810 MEDIUM
Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover
CVSS 5.3
CVE-2026-2028 MEDIUM
Maxi Blocks <= 2.1.8 - Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter
CVSS 5.3
CVE-2026-31956 MEDIUM
Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level authorization
CVSS 4.3
CVE-2026-6375 HIGH
Authorization bypass through User-Controlled key in SpiceJet Online Booking System
CVE-2026-41279 HIGH
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
CVE-2026-41277 HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41267 HIGH
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
CVSS 8.1
CVE-2026-5750 HIGH
Insecure direct object reference (IDOR) vulnerability in Fullstep
CVE-2026-41127 MEDIUM
BigBlueButton's missing authorization allows viewer to inject/overwrite captions
CVSS 6.5
Details
Vulnerabilities 1,570
Exploit Likelihood High