CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,105 vulnerabilities with CWE-639
CVE-2026-13512 MEDIUM
Databend Tenant client_session_manager.rs state_key authorization
CVSS 6.3
CVE-2026-13490 LOW
glpi-project glpi Document document.send.php canViewFile authorization
CVSS 3.7
CVE-2026-11987 MEDIUM
Dokan WooCommerce Multivendor Marketplace <= 5.0.4 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-52782 CRITICAL
OpenProject < 17.3.3 and 17.4.0 - Insecure Direct Object Reference
CVSS 9.9
CVE-2026-52779 MEDIUM
OpenProject Calendar and Team Planner - Cross-Project Authorization Bypass
CVSS 5.4
CVE-2026-49355 MEDIUM
OpenProject: Private work package data disclosure through single meeting agenda item API
CVSS 4.3
CVE-2026-44736 MEDIUM
OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
CVSS 6.5
CVE-2026-44732 MEDIUM
OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources
CVSS 4.3
CVE-2026-44731 MEDIUM
OpenProject Meetings - User Enumeration via Improper Access Control
CVSS 4.3
CVE-2026-56823 MEDIUM
AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering
CVSS 5.4
CVE-2026-12411 HIGH
Broken Access Control in Canonical LXD DevLXD API
CVSS 8.4
CVE-2026-57665 MEDIUM
WordPress GravityView plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-57652 MEDIUM
WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-57646 MEDIUM
WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.4
CVE-2026-57634 MEDIUM
WordPress PPWP plugin <= 1.9.19 - Insecure Direct Object References (IDOR) vulnerability
CVSS 4.3
CVE-2026-57630 MEDIUM
WordPress Blocksy Companion Pro plugin <= 2.1.46 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-56069 HIGH
WordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.5
CVE-2026-56048 MEDIUM
WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-54839 HIGH
WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups plugin <= 2.0.9 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-54826 HIGH
WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.6
CVE-2026-56774 MEDIUM
Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID
CVSS 5.4
CVE-2026-56772 MEDIUM
NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions Endpoint
CVSS 4.3
CVE-2026-54097 HIGH
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-9799 MEDIUM
Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass
CVSS 4.6
CVE-2026-9099 HIGH
Keycloak: group-admin escalation to realm-admin
CVSS 7.7
Details
Vulnerabilities 2,105
Exploit Likelihood High