CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,777 vulnerabilities with CWE-639
CVE-2026-2888
MEDIUM
Formidable Forms WordPress Plugin <=6.28 - Auth Bypass
CVSS 5.3
CVE-2026-2879
MEDIUM
GetGenie WordPress Plugin <=4.3.2 - Insecure Direct Object Reference
CVSS 5.4
CVE-2026-2257
MEDIUM
GetGenie WordPress Plugin <=4.3.2 - Stored XSS
CVSS 6.4
CVE-2026-1704
MEDIUM
Appointment Booking Calendar <1.6.9.29 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-2366
LOW
Red Hat build of Keycloak 26.4 - Authenticated Authorization Bypass in Admin API
CVSS 3.1
CVE-2026-32131
HIGH
ZITADEL <3.4.8/4.12.2 - Info Disclosure
CVSS 7.7
CVE-2026-27591
CRITICAL
Winter CMS <1.0.477/1.1.12/1.2.12 - Privilege Escalation
CVSS 9.9
CVE-2026-32104
MEDIUM
StudioCMS <0.4.3 - Privilege Escalation
CVSS 5.4
CVE-2026-32103
MEDIUM
StudioCMS <0.4.3 - Privilege Escalation
CVSS 6.8
CVE-2026-32097
HIGH
PingPong < 7.27.2 - Authenticated Authorization Bypass via File Retrieval and Deletion
CVSS 8.8
CVE-2026-31874
CRITICAL
Taskosaur 1.0.0 - Privilege Escalation
CVSS 9.8
CVE-2026-31867
MEDIUM
Craft Commerce <4.11.0/5.6.0 - IDOR
CVSS 4.8
CVE-2026-1992
HIGH
ExactMetrics 8.6.0-9.0.2 - Auth Bypass
CVSS 8.8
CVE-2026-2918
MEDIUM
Happy Addons for Elementor <3.21.0 - Privilege Escalation
CVSS 6.4
CVE-2026-2917
MEDIUM
Happy Addons for Elementor <3.21.0 - IDOR
CVSS 5.4
CVE-2026-1753
MEDIUM
Gutena Forms <1.6.1 - Privilege Escalation
CVSS 6.8
CVE-2026-3453
HIGH
ProfilePress <=4.16.11 - Insecure Direct Object Reference
CVSS 8.1
CVE-2026-31832
MEDIUM
Umbraco 14.0.0-16.5.0/17.0.0-17.2.1 - Privilege Escalation
CVSS 5.4
CVE-2026-31820
MEDIUM
Sylius < 2.0.16, 2.1.12, 2.2.3 - Shop LiveComponents IDOR
CVSS 6.5
CVE-2026-30954
MEDIUM
LinkAce <=2.1.0 - Privilege Escalation
CVSS 4.3
CVE-2026-3306
MEDIUM
GitHub Enterprise Server - Privilege Escalation
CVSS 4.3
CVE-2026-30969
CRITICAL
Coral Server < 1.1.0 - Unauthenticated Session Impersonation via Weak Session Identifier
CVSS 9.1
CVE-2026-30959
MEDIUM
OneUptime < 10.0.21 - Authenticated Authorization Bypass via Resend-Verification-Code Endpoint
CVSS 5.0
CVE-2026-30945
HIGH
StudioCMS <0.4.0 - Privilege Escalation
CVSS 7.1
CVE-2026-30944
HIGH
StudioCMS <0.4.0 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
1,777
Exploit Likelihood
High