CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,105 vulnerabilities with CWE-639
CVE-2026-55411
MEDIUM
ToolJet < 3.20.1780-lts - Cross-Tenant Credential Decryption
CVSS 6.8
CVE-2026-13350
LOW
Pretix Venueless < 0a35457f - Authorization Bypass Through User-Controlled Key
CVE-2026-56013
MEDIUM
WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-5309
MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 5.4
CVE-2026-52812
HIGH
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52799
HIGH
Gogs: Missing Authorization in Attachment Download
CVSS 7.5
CVE-2026-55583
HIGH
Twenty: Cross-workspace IDOR in AgentTurnResolver
CVSS 7.6
CVE-2026-27708
HIGH
FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
CVE-2026-55611
NONE
AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without ownership scoping (cross-tenant IDOR deletion)
CVE-2026-47388
LOW
NocoDB: Missing Ownership Check in MCP Attachment Read
CVE-2026-47378
MEDIUM
NocoDB: Hidden Column Exposure in Public Shared View Endpoints
CVE-2026-54322
HIGH
Daytona < 0.185.0 - Cross-Organization Role IDOR
CVSS 7.7
CVE-2026-54324
MEDIUM
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVSS 6.5
CVE-2026-54016
MEDIUM
Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
CVSS 4.3
CVE-2026-54015
MEDIUM
Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
CVSS 6.4
CVE-2026-54010
HIGH
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVSS 8.3
CVE-2026-54009
MEDIUM
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVSS 6.5
CVE-2026-54006
MEDIUM
Open WebUI: Calendar event re-parenting allows writing events into another user's calendar
CVSS 4.3
CVE-2026-55255
HIGH
KEV
Langflow < 1.9.2 - Authenticated Insecure Direct Object Reference
CVSS 8.4
CVE-2026-45732
HIGH
n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVSS 8.1
CVE-2026-33760
HIGH
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVSS 8.8
CVE-2026-56784
HIGH
OpenRemote Manager - Cross-Tenant IDOR in Bulk Alarm Deletion
CVSS 8.1
CVE-2026-56222
HIGH
Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings
CVSS 7.2
CVE-2026-48067
MEDIUM
Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields
CVSS 6.5
CVE-2026-6062
MEDIUM
Mattermost - IDOR in Jira Plugin Subscription Edit Endpoint
CVSS 6.4
Details
Vulnerabilities
2,105
Exploit Likelihood
High