CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,779 vulnerabilities with CWE-639
CVE-2026-25005 MEDIUM
N-Media Frontend File Manager <=23.5 - Auth Bypass
CVSS 5.3
CVE-2026-25120 LOW
Gogs < 0.14.0 - Authorization Bypass via DeleteComment API
CVSS 2.7
CVE-2026-2230 MEDIUM
Booking Calendar Plugin <10.14.14 - IDOR
CVSS 4.3
CVE-2026-1436 MEDIUM
Graylog 2.2.3 - Privilege Escalation
CVSS 6.5
CVE-2026-1987 MEDIUM
Scheduler Widget plugin <0.1.6 - Insecure Direct Object Reference
CVSS 5.4
CVE-2026-1619 HIGH
Universal Software Inc. FlexCity/Kiosk <1.0.36 - Auth Bypass
CVSS 8.3
CVE-2026-1080 MEDIUM
GitLab 16.7-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Authenticated Authorization Bypass via Iterations API
CVSS 4.3
CVE-2026-25530 MEDIUM
Kanboard < 1.2.50 - Authenticated Authorization Bypass via getSwimlane API
CVSS 4.3
CVE-2026-25497 HIGH
Craft CMS GraphQL API - Cross-Volume Asset Privilege Escalation
CVSS 8.8
CVE-2026-24900 MEDIUM
Markus < 2.9.1 - Authorization Bypass via Submission File ID Parameter
CVSS 6.5
CVE-2026-25567 MEDIUM
WeKan < 8.19 - Authenticated Comment Author Spoofing via authorId Parameter
CVSS 4.3
CVE-2026-25564 HIGH
WeKan < 8.19 - Insecure Direct Object Reference via Checklist Card-Board Relationship Tampering
CVSS 7.5
CVE-2026-25563 HIGH
WeKan < 8.19 - Authorization Bypass via Checklist Creation IDOR
CVSS 7.5
CVE-2026-25757 MEDIUM
Spree < 5.0.8 - Unauthenticated Order Information Disclosure via Order ID
CVSS 5.3
CVE-2026-25758 HIGH
Spree < 4.10.3 - Unauthenticated Insecure Direct Object Reference in Guest Checkout Address Binding
CVSS 7.5
CVE-2026-25574 MEDIUM
Payload < 3.74.0 - Authenticated Insecure Direct Object Reference in Preferences Collection
CVSS 5.4
CVE-2026-24776 MEDIUM
OpenProject <17.0.2 - Info Disclosure
CVSS 4.3
CVE-2026-2010 MEDIUM
Sanluan PublicCMS <4.0-6.202506.d - Privilege Escalation
CVSS 4.2
CVE-2026-1228 MEDIUM
Timeline Block <1.3.3 - Info Disclosure
CVSS 4.3
CVE-2026-1271 MEDIUM
ProfileGrid - User Profiles, Groups and Communities <5.9.7.2 - Inse...
CVSS 5.3
CVE-2026-24773 HIGH
Open eClass Platform < 4.2 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
CVE-2026-24991 MEDIUM
HT Plugins Extensions For CF7 <3.4.0 - Auth Bypass
CVSS 5.3
CVE-2026-1664 MEDIUM
npm agents < 0.3.7 - Insecure Direct Object Reference via Email Header Spoofing
CVE-2026-1375 HIGH
Tutor LMS <=3.9.5 - Instructor Course IDOR
CVSS 8.1
CVE-2026-0909 MEDIUM
WP ULike <4.8.3.1 - Insecure Direct Object Reference
CVSS 5.3
Details
Vulnerabilities 1,779
Exploit Likelihood High