CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,100 vulnerabilities with CWE-639
CVE-2026-68501
MEDIUM
Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII
CVSS 6.5
CVE-2026-68500
HIGH
Sylius Mollie Plugin: Payment status forgery via the payment webhook
CVSS 7.5
CVE-2026-10700
MEDIUM
Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files
CVSS 6.5
CVE-2026-12945
HIGH
Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
CVSS 7.1
CVE-2026-67348
HIGH
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
CVSS 8.1
CVE-2026-15257
MEDIUM
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification
CVSS 5.3
CVE-2026-15255
MEDIUM
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
CVSS 5.3
CVE-2026-14310
MEDIUM
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
CVSS 5.4
CVE-2026-14223
MEDIUM
Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR
CVSS 4.3
CVE-2026-13345
MEDIUM
Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
CVSS 5.3
CVE-2026-13178
HIGH
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVSS 7.5
CVE-2026-13145
MEDIUM
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVSS 4.3
CVE-2026-5060
MEDIUM
MasterStudy LMS WordPress Plugin <= 3.7.14 - Instructor Attachment Deletion
CVSS 6.5
CVE-2026-63242
MEDIUM
Three Learning Koollab LMS - Business Logic Vulnerability
CVSS 4.3
CVE-2026-63241
LOW
Three Learning Koollab LMS - Insecure Direct Object Reference Vulnerability
CVSS 3.1
CVE-2026-14224
MEDIUM
Easy Appointments <= 3.12.26 - Subscriber+ Cross-User Appointment Data Modification via IDOR
CVSS 5.4
CVE-2026-57510
HIGH
SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
CVSS 8.8
CVE-2026-49258
HIGH
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
CVSS 8.8
CVE-2026-18028
LOW
pretix - Missing Authorization Check in Event Quick Setup View
CVE-2026-16797
MEDIUM
ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
CVSS 4.3
CVE-2026-59240
MEDIUM
IDOR in Prospero Flow CRM allows deletion of other users' notifications
CVE-2026-48052
MEDIUM
Papra: Cross-organization tag deletion and modification via authenticated cross-tenant request
CVSS 5.4
CVE-2026-17570
MEDIUM
Devolutions Server - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2026-17531
MEDIUM
unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
CVSS 5.0
CVE-2026-59546
HIGH
WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability
CVSS 7.4
Details
Vulnerabilities
2,100
Exploit Likelihood
High