CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,105 vulnerabilities with CWE-639
CVE-2026-55411 MEDIUM
ToolJet < 3.20.1780-lts - Cross-Tenant Credential Decryption
CVSS 6.8
CVE-2026-13350 LOW
Pretix Venueless < 0a35457f - Authorization Bypass Through User-Controlled Key
CVE-2026-56013 MEDIUM
WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-5309 MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 5.4
CVE-2026-52812 HIGH
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52799 HIGH
Gogs: Missing Authorization in Attachment Download
CVSS 7.5
CVE-2026-55583 HIGH
Twenty: Cross-workspace IDOR in AgentTurnResolver
CVSS 7.6
CVE-2026-27708 HIGH
FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
CVE-2026-55611 NONE
AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without ownership scoping (cross-tenant IDOR deletion)
CVE-2026-47388 LOW
NocoDB: Missing Ownership Check in MCP Attachment Read
CVE-2026-47378 MEDIUM
NocoDB: Hidden Column Exposure in Public Shared View Endpoints
CVE-2026-54322 HIGH
Daytona < 0.185.0 - Cross-Organization Role IDOR
CVSS 7.7
CVE-2026-54324 MEDIUM
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVSS 6.5
CVE-2026-54016 MEDIUM
Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
CVSS 4.3
CVE-2026-54015 MEDIUM
Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
CVSS 6.4
CVE-2026-54010 HIGH
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVSS 8.3
CVE-2026-54009 MEDIUM
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVSS 6.5
CVE-2026-54006 MEDIUM
Open WebUI: Calendar event re-parenting allows writing events into another user's calendar
CVSS 4.3
CVE-2026-55255 HIGH KEV
Langflow < 1.9.2 - Authenticated Insecure Direct Object Reference
CVSS 8.4
CVE-2026-45732 HIGH
n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVSS 8.1
CVE-2026-33760 HIGH
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVSS 8.8
CVE-2026-56784 HIGH
OpenRemote Manager - Cross-Tenant IDOR in Bulk Alarm Deletion
CVSS 8.1
CVE-2026-56222 HIGH
Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings
CVSS 7.2
CVE-2026-48067 MEDIUM
Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields
CVSS 6.5
CVE-2026-6062 MEDIUM
Mattermost - IDOR in Jira Plugin Subscription Edit Endpoint
CVSS 6.4
Details
Vulnerabilities 2,105
Exploit Likelihood High