CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,105 vulnerabilities with CWE-639
CVE-2026-13512
MEDIUM
Databend Tenant client_session_manager.rs state_key authorization
CVSS 6.3
CVE-2026-13490
LOW
glpi-project glpi Document document.send.php canViewFile authorization
CVSS 3.7
CVE-2026-11987
MEDIUM
Dokan WooCommerce Multivendor Marketplace <= 5.0.4 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-52782
CRITICAL
OpenProject < 17.3.3 and 17.4.0 - Insecure Direct Object Reference
CVSS 9.9
CVE-2026-52779
MEDIUM
OpenProject Calendar and Team Planner - Cross-Project Authorization Bypass
CVSS 5.4
CVE-2026-49355
MEDIUM
OpenProject: Private work package data disclosure through single meeting agenda item API
CVSS 4.3
CVE-2026-44736
MEDIUM
OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
CVSS 6.5
CVE-2026-44732
MEDIUM
OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter "project_id" leads to Unauthorized Modification of Resources
CVSS 4.3
CVE-2026-44731
MEDIUM
OpenProject Meetings - User Enumeration via Improper Access Control
CVSS 4.3
CVE-2026-56823
MEDIUM
AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering
CVSS 5.4
CVE-2026-12411
HIGH
Broken Access Control in Canonical LXD DevLXD API
CVSS 8.4
CVE-2026-57665
MEDIUM
WordPress GravityView plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-57652
MEDIUM
WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-57646
MEDIUM
WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.4
CVE-2026-57634
MEDIUM
WordPress PPWP plugin <= 1.9.19 - Insecure Direct Object References (IDOR) vulnerability
CVSS 4.3
CVE-2026-57630
MEDIUM
WordPress Blocksy Companion Pro plugin <= 2.1.46 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-56069
HIGH
WordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.5
CVE-2026-56048
MEDIUM
WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-54839
HIGH
WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups plugin <= 2.0.9 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-54826
HIGH
WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.6
CVE-2026-56774
MEDIUM
Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID
CVSS 5.4
CVE-2026-56772
MEDIUM
NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions Endpoint
CVSS 4.3
CVE-2026-54097
HIGH
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-9799
MEDIUM
Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass
CVSS 4.6
CVE-2026-9099
HIGH
Keycloak: group-admin escalation to realm-admin
CVSS 7.7
Details
Vulnerabilities
2,105
Exploit Likelihood
High