CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,105 vulnerabilities with CWE-639
CVE-2026-5138 MEDIUM
Foreman: foreman: information disclosure via improper validation of nested request parameters
CVSS 4.3
CVE-2026-5135 MEDIUM
Foreman: foreman: unauthorized modification of host configurations via broken access control
CVSS 6.5
CVE-2026-53903 HIGH
MyComplianceOffice - Insecure Direct Object Reference in MCO
CVSS 8.1
CVE-2026-10096 MEDIUM
Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
CVSS 4.3
CVE-2026-12904 MEDIUM
Kadence Blocks <= 3.7.7 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2026-11988 MEDIUM
LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
CVSS 6.5
CVE-2026-56230 HIGH
Capgo - Broken Object Level Authorization via x-limited-key-id Header
CVSS 8.8
CVE-2026-58447 MEDIUM
Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check
CVSS 6.5
CVE-2026-10140 CRITICAL
Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem
CVSS 9.6
CVE-2026-27956 MEDIUM
Coolify: Cross-team application domain enumeration via domains_by_server endpoint
CVSS 4.3
CVE-2026-27883 MEDIUM
Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure
CVSS 5.0
CVE-2026-27881 MEDIUM
Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} (IDOR)
CVSS 5.0
CVE-2026-14209 MEDIUM
Keycloak-admin-ui: keycloak-admin-ui: keycloak: admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
CVSS 4.3
CVE-2026-12073 CRITICAL
ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
CVSS 9.8
CVE-2026-34592 HIGH
Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure
CVSS 7.7
CVE-2026-57498 CRITICAL
Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams' Servers
CVSS 9.6
CVE-2026-57956 MEDIUM
SigNoz 0.130.1 - Cross-Organization Insecure Direct Object Reference in Alert Rules
CVSS 6.4
CVE-2026-57945 MEDIUM
PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{uid} Endpoint
CVSS 4.3
CVE-2026-57943 MEDIUM
LibrePhotos < 1.0.0 - Insecure Direct Object Reference in SetPhotosShared Endpoint
CVSS 5.9
CVE-2026-56781 MEDIUM
Teable - Unauthenticated Hidden Field Disclosure via Projection Parameter Override
CVSS 5.3
CVE-2026-56780 HIGH
Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API
CVSS 7.5
CVE-2026-57341 MEDIUM
WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.9.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-57676 MEDIUM
WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object References (IDOR) vulnerability
CVSS 4.3
CVE-2026-13549 MEDIUM
CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
CVSS 5.4
CVE-2026-13534 MEDIUM
CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
CVSS 5.0
Details
Vulnerabilities 2,105
Exploit Likelihood High