CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,777 vulnerabilities with CWE-639
CVE-2026-30927 MEDIUM
Admidio <5.0.6 - Privilege Escalation
CVSS 5.4
CVE-2026-30920 HIGH
OneUptime < 10.0.19 - Missing Authorization in GitHub App Callback
CVSS 8.6
CVE-2026-30885 MEDIUM
WWBN AVideo <25.0 - Info Disclosure
CVSS 5.3
CVE-2026-28433 MEDIUM
Misskey 10.93.0-2026.3.0 - Auth Bypass
CVSS 4.3
CVE-2026-30857 MEDIUM
WeKnora < 0.3.0 - Authenticated Cross-Tenant Authorization Bypass via Knowledge Base Copy Endpoint
CVSS 5.3
CVE-2026-30825 NONE
Hoppscotch <2026.2.1 - Privilege Escalation
CVE-2026-30823 HIGH
Flowise < 3.0.13 - Unauthenticated IDOR and Account Takeover via SSO Configuration
CVSS 8.8
CVE-2026-30231 MEDIUM
Flare < 1.7.2 - Authenticated Authorization Bypass via Raw and Direct File Routes
CVSS 5.3
CVE-2026-30230 HIGH
Flare < 1.7.2 - Unauthenticated Password Bypass in Thumbnail Endpoint
CVSS 7.5
CVE-2026-30843 MEDIUM
Wekan 8.32-8.33 - Authenticated Insecure Direct Object Reference in Custom Fields Endpoint
CVSS 6.5
CVE-2026-25877 MEDIUM
Chartbrew <4.8.1 - Privilege Escalation
CVSS 6.5
CVE-2026-28469 HIGH
OpenClaw < 2026.2.14 - Authorization Bypass via Google Chat Webhook Path Ambiguity
CVSS 7.5
CVE-2026-27898 MEDIUM
Vaultwarden <1.35.4 - Info Disclosure
CVSS 5.4
CVE-2026-29069 MEDIUM
Craft CMS <5.9.0-beta.2/4.17.0-beta.2 - Auth Bypass
CVSS 5.3
CVE-2026-28782 MEDIUM
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - Privilege Escalation
CVSS 4.3
CVE-2026-28781 MEDIUM
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5
CVE-2026-28696 HIGH
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Info Disclosure
CVSS 7.5
CVE-2026-0020 HIGH
ParsedPermissionUtils - Privilege Escalation
CVSS 8.4
CVE-2026-28361 MEDIUM
NocoDB <0.301.3 - Privilege Escalation
CVSS 6.3
CVE-2026-28354 MEDIUM
ClipBucket <5.5.3 #59 - Privilege Escalation
CVSS 6.5
CVE-2026-27793 MEDIUM
seerr < 3.1.0 - Authenticated Information Disclosure via User Settings Endpoint
CVSS 6.5
CVE-2026-25147 HIGH
OpenEMR < 8.0.0 - Horizontal Privilege Escalation via Patient ID Override
CVSS 7.1
CVE-2026-1558 MEDIUM
WP Recipe Maker <= 10.3.2 - Unauthenticated Insecure Direct Object Reference via Instacart Integration API
CVSS 5.3
CVE-2026-28225 MEDIUM
Manyfold < 0.133.1 - Authorization Bypass via ModelFilesController get_model Method
CVSS 5.3
CVE-2026-28217 MEDIUM
hoppscotch < 2026.2.0 - Authenticated Insecure Direct Object Reference via userCollection GraphQL Query
CVSS 6.5
Details
Vulnerabilities 1,777
Exploit Likelihood High