CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,572 vulnerabilities with CWE-639
CVE-2026-1375 HIGH
Tutor LMS - IDOR
CVSS 8.1
CVE-2026-0909 MEDIUM
WP ULike <4.8.3.1 - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-1733 MEDIUM
Crmeb < 5.6.3 - Improper Authorization
CVSS 4.3
CVE-2026-1251 MEDIUM
SupportCandy - Helpdesk & Customer Support Ticket System <3.4.4 - I...
CVSS 5.4
CVE-2026-1389 MEDIUM
Document Embedder <2.0.4 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-24134 MEDIUM
StudioCMS <0.2.0 - Privilege Escalation
CVSS 6.5
CVE-2026-1213 MEDIUM
Pypi Askbot < 0.12.3 - IDOR
CVSS 4.3
CVE-2026-24136 HIGH
Saleor <3.22.28 - Info Disclosure
CVSS 7.5
CVE-2026-24634 MEDIUM
Rustaurius Ultimate Reviews <3.2.16 - Auth Bypass
CVSS 5.3
CVE-2026-24631 MEDIUM
Mikado-Themes Rosebud <1.4 - Auth Bypass
CVSS 5.4
CVE-2026-24599 MEDIUM
XLPlugins NextMove Lite <2.23.0 - Auth Bypass
CVSS 5.3
CVE-2026-20912 CRITICAL
Gitea - Info Disclosure
CVSS 9.1
CVE-2026-20904 MEDIUM
Gitea - Privilege Escalation
CVSS 6.5
CVE-2026-20897 CRITICAL
Gitea - Info Disclosure
CVSS 9.1
CVE-2026-1201 CRITICAL
Hubitat Elevation <2.4.2.157 - Auth Bypass
CVE-2026-24379 MEDIUM
WP Job Portal <2.4.3 - Auth Bypass
CVSS 6.5
CVE-2026-22430 MEDIUM
Mikado-Themes Verdure <1.7 - Auth Bypass
CVSS 5.4
CVE-2026-22426 MEDIUM
Elated-Themes Sweet Jane <1.3 - Auth Bypass
CVSS 5.4
CVE-2026-22411 LOW
Mikado-Themes Dolcino - Auth Bypass
CVSS 3.8
CVE-2026-22409 LOW
Mikado-Themes Justicia <1.3 - Auth Bypass
CVSS 3.8
CVE-2026-22407 LOW
Mikado-Themes Roam <2.1.1 - Auth Bypass
CVSS 3.8
CVE-2026-22406 LOW
Mikado-Themes Overton - Auth Bypass
CVSS 3.8
CVE-2026-22404 LOW
Mikado-Themes Innovio <1.8 - Auth Bypass
CVSS 3.8
CVE-2026-22400 MEDIUM
Mikado-Themes Holmes <1.8 - Auth Bypass
CVSS 5.4
CVE-2026-22398 MEDIUM
Mikado-Themes Fleur - Auth Bypass
CVSS 5.4
Details
Vulnerabilities 1,572
Exploit Likelihood High