CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,570 vulnerabilities with CWE-639
CVE-2026-7510
MEDIUM
OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization
CVSS 6.3
CVE-2026-6542
MEDIUM
Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id
CVSS 6.5
CVE-2026-7502
MEDIUM
LinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization
CVSS 5.4
CVE-2026-4503
HIGH
Unauthenticated Insecure Direct Object Reference (IDOR) Vulnerability in Langflow Desktop Image Download Endpoint
CVSS 7.5
CVE-2026-40600
HIGH
Chartbrew: Incorrect Access Control in project share policy routes via unbound policy_id
CVSS 8.1
CVE-2026-7399
HIGH
IDOR in MeWare Software's PDKS
CVSS 8.1
CVE-2026-42517
HIGH
Cryptographic Failure Vulnerability in e-Sushrut HMIS
CVE-2026-42516
HIGH
Broken Access Control Vulnerability in e-Sushrut HMIS
CVE-2026-42515
HIGH
Insecure Direct Object Reference (IDOR) Vulnerability in e-Sushrut HMIS
CVE-2026-41649
HIGH
Outline has IDOR in document share creation that allows unauthorized access to private documents across workspaces
CVSS 7.7
CVE-2026-41406
MEDIUM
OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted Messages
CVSS 5.4
CVE-2026-24178
CRITICAL
Nvidia Flare SDK - Authorization Bypass
CVSS 9.8
CVE-2026-41372
MEDIUM
OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery
CVSS 5.8
CVE-2026-28747
HIGH
Milesight Cameras Authorization Bypass Through User-Controlled Key
CVSS 7.1
CVE-2026-7145
MEDIUM
mettle sendportal Invitation WorkspaceInvitationsController.php destroy authorization
CVSS 5.4
CVE-2026-7144
MEDIUM
1000 Projects Portfolio Management System MCA update_passwd_process.php authorization
CVSS 4.3
CVE-2026-6810
MEDIUM
Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover
CVSS 5.3
CVE-2026-2028
MEDIUM
Maxi Blocks <= 2.1.8 - Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter
CVSS 5.3
CVE-2026-31956
MEDIUM
Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level authorization
CVSS 4.3
CVE-2026-6375
HIGH
Authorization bypass through User-Controlled key in SpiceJet Online Booking System
CVE-2026-41279
HIGH
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
CVE-2026-41277
HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41267
HIGH
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
CVSS 8.1
CVE-2026-5750
HIGH
Insecure direct object reference (IDOR) vulnerability in Fullstep
CVE-2026-41127
MEDIUM
BigBlueButton's missing authorization allows viewer to inject/overwrite captions
CVSS 6.5
Details
Vulnerabilities
1,570
Exploit Likelihood
High