CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,105 vulnerabilities with CWE-639
CVE-2026-5138
MEDIUM
Foreman: foreman: information disclosure via improper validation of nested request parameters
CVSS 4.3
CVE-2026-5135
MEDIUM
Foreman: foreman: unauthorized modification of host configurations via broken access control
CVSS 6.5
CVE-2026-53903
HIGH
MyComplianceOffice - Insecure Direct Object Reference in MCO
CVSS 8.1
CVE-2026-10096
MEDIUM
Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
CVSS 4.3
CVE-2026-12904
MEDIUM
Kadence Blocks <= 3.7.7 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2026-11988
MEDIUM
LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
CVSS 6.5
CVE-2026-56230
HIGH
Capgo - Broken Object Level Authorization via x-limited-key-id Header
CVSS 8.8
CVE-2026-58447
MEDIUM
Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check
CVSS 6.5
CVE-2026-10140
CRITICAL
Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem
CVSS 9.6
CVE-2026-27956
MEDIUM
Coolify: Cross-team application domain enumeration via domains_by_server endpoint
CVSS 4.3
CVE-2026-27883
MEDIUM
Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure
CVSS 5.0
CVE-2026-27881
MEDIUM
Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} (IDOR)
CVSS 5.0
CVE-2026-14209
MEDIUM
Keycloak-admin-ui: keycloak-admin-ui: keycloak: admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
CVSS 4.3
CVE-2026-12073
CRITICAL
ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
CVSS 9.8
CVE-2026-34592
HIGH
Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure
CVSS 7.7
CVE-2026-57498
CRITICAL
Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams' Servers
CVSS 9.6
CVE-2026-57956
MEDIUM
SigNoz 0.130.1 - Cross-Organization Insecure Direct Object Reference in Alert Rules
CVSS 6.4
CVE-2026-57945
MEDIUM
PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{uid} Endpoint
CVSS 4.3
CVE-2026-57943
MEDIUM
LibrePhotos < 1.0.0 - Insecure Direct Object Reference in SetPhotosShared Endpoint
CVSS 5.9
CVE-2026-56781
MEDIUM
Teable - Unauthenticated Hidden Field Disclosure via Projection Parameter Override
CVSS 5.3
CVE-2026-56780
HIGH
Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API
CVSS 7.5
CVE-2026-57341
MEDIUM
WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.9.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-57676
MEDIUM
WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object References (IDOR) vulnerability
CVSS 4.3
CVE-2026-13549
MEDIUM
CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
CVSS 5.4
CVE-2026-13534
MEDIUM
CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
CVSS 5.0
Details
Vulnerabilities
2,105
Exploit Likelihood
High