CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,100 vulnerabilities with CWE-639
CVE-2026-68501 MEDIUM
Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII
CVSS 6.5
CVE-2026-68500 HIGH
Sylius Mollie Plugin: Payment status forgery via the payment webhook
CVSS 7.5
CVE-2026-10700 MEDIUM
Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files
CVSS 6.5
CVE-2026-12945 HIGH
Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
CVSS 7.1
CVE-2026-67348 HIGH
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
CVSS 8.1
CVE-2026-15257 MEDIUM
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification
CVSS 5.3
CVE-2026-15255 MEDIUM
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
CVSS 5.3
CVE-2026-14310 MEDIUM
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
CVSS 5.4
CVE-2026-14223 MEDIUM
Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR
CVSS 4.3
CVE-2026-13345 MEDIUM
Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
CVSS 5.3
CVE-2026-13178 HIGH
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVSS 7.5
CVE-2026-13145 MEDIUM
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVSS 4.3
CVE-2026-5060 MEDIUM
MasterStudy LMS WordPress Plugin <= 3.7.14 - Instructor Attachment Deletion
CVSS 6.5
CVE-2026-63242 MEDIUM
Three Learning Koollab LMS - Business Logic Vulnerability
CVSS 4.3
CVE-2026-63241 LOW
Three Learning Koollab LMS - Insecure Direct Object Reference Vulnerability
CVSS 3.1
CVE-2026-14224 MEDIUM
Easy Appointments <= 3.12.26 - Subscriber+ Cross-User Appointment Data Modification via IDOR
CVSS 5.4
CVE-2026-57510 HIGH
SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
CVSS 8.8
CVE-2026-49258 HIGH
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
CVSS 8.8
CVE-2026-18028 LOW
pretix - Missing Authorization Check in Event Quick Setup View
CVE-2026-16797 MEDIUM
ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
CVSS 4.3
CVE-2026-59240 MEDIUM
IDOR in Prospero Flow CRM allows deletion of other users' notifications
CVE-2026-48052 MEDIUM
Papra: Cross-organization tag deletion and modification via authenticated cross-tenant request
CVSS 5.4
CVE-2026-17570 MEDIUM
Devolutions Server - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2026-17531 MEDIUM
unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
CVSS 5.0
CVE-2026-59546 HIGH
WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability
CVSS 7.4
Details
Vulnerabilities 2,100
Exploit Likelihood High