CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,570 vulnerabilities with CWE-639
CVE-2026-5845
CRITICAL
Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server
CVSS 9.6
CVE-2026-3307
LOW
Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
CVSS 2.7
CVE-2026-40907
MEDIUM
WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens
CVSS 6.5
CVE-2026-40867
HIGH
Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
CVE-2026-40866
HIGH
Horilla: Unauthorized Document Overwrite via File Upload Endpoint
CVE-2026-40865
HIGH
Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
CVE-2026-5652
CRITICAL
Authorization Bypass Through User-Controlled Key in Crafty Controller
CVSS 9.0
CVE-2026-40591
HIGH
FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Customer Modification
CVSS 7.1
CVE-2026-40590
MEDIUM
FreeScout's Customer AJAX Create Modifies Hidden Existing Customer
CVSS 4.3
CVE-2026-40589
HIGH
FreeScout has Customer Edit Cross-Mailbox Email Takeover
CVSS 7.6
CVE-2026-40570
MEDIUM
FreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Full Customer PII
CVE-2026-39386
HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-40896
MEDIUM
OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup
CVSS 6.5
CVE-2026-6614
MEDIUM
TransformerOptimus SuperAGI project.py get_projects_organisation authorization
CVSS 6.3
CVE-2026-6613
MEDIUM
TransformerOptimus SuperAGI agent.py get_schedule_data authorization
CVSS 6.3
CVE-2026-6612
MEDIUM
TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization
CVSS 6.3
CVE-2026-6586
MEDIUM
TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization
CVSS 6.3
CVE-2026-6585
MEDIUM
TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization
CVSS 5.4
CVE-2026-6584
MEDIUM
TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization
CVSS 5.4
CVE-2026-6583
MEDIUM
TransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization
CVSS 5.4
CVE-2026-6571
MEDIUM
kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
CVSS 6.3
CVE-2026-6570
LOW
kodcloud KodExplorer systemMember.class.php initInstall authorization
CVSS 2.7
CVE-2026-40480
HIGH
ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`
CVE-2026-5234
MEDIUM
LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
CVSS 5.3
CVE-2026-40308
HIGH
My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog
Details
Vulnerabilities
1,570
Exploit Likelihood
High