CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,105 vulnerabilities with CWE-639
CVE-2026-56424
HIGH
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
CVE-2026-56422
CRITICAL
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
CVE-2026-56385
MEDIUM
Craft CMS - Authorization Bypass in assets/preview-file Endpoint
CVSS 4.3
CVE-2026-56229
MEDIUM
Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs
CVSS 6.5
CVE-2026-56215
HIGH
Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning
CVSS 8.3
CVE-2026-49339
HIGH
Sentriz Gonic < 0.21.0 - Authenticated Playlist Path Traversal
CVSS 7.1
CVE-2026-49338
HIGH
Sentriz Gonic < 0.21.0 - Authenticated Private Playlist Disclosure and Deletion
CVSS 7.1
CVE-2026-54105
MEDIUM
U.S. GAO EPDS and CBCA EDS user information disclosure
CVSS 5.3
CVE-2026-50141
HIGH
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
CVE-2026-12102
LOW
UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter
CVSS 2.7
CVE-2026-10623
MEDIUM
PressPrimer Quiz < 2.3.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-10023
MEDIUM
Dokan < 5.0.3 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-48759
HIGH
TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)
CVSS 7.1
CVE-2026-50194
HIGH
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVSS 8.2
CVE-2026-55198
MEDIUM
Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint
CVSS 6.5
CVE-2026-55197
MEDIUM
Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint
CVSS 6.5
CVE-2026-54184
HIGH
WordPress Clean Login plugin <= 1.15 - Insecure Direct Object References (IDOR) vulnerability
CVSS 8.2
CVE-2026-48783
MEDIUM
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
CVSS 4.8
CVE-2026-40768
HIGH
WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.3
CVE-2026-53863
HIGH
OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy
CVSS 7.1
CVE-2026-10780
MEDIUM
Static Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode 'id' Attribute
CVSS 4.3
CVE-2026-48599
HIGH
Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding
CVE-2026-52699
HIGH
WordPress VikRentCar plugin <= 1.4.5 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.5
CVE-2026-48872
HIGH
WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerability
CVSS 7.5
CVE-2026-48868
HIGH
WordPress Simple Shopping Cart plugin <= 5.2.9 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.5
Details
Vulnerabilities
2,105
Exploit Likelihood
High