CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,100 vulnerabilities with CWE-639
CVE-2026-59539 HIGH
WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (IDOR) vulnerability
CVSS 7.5
CVE-2026-17527 HIGH
Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone
CVSS 7.7
CVE-2026-66412 MEDIUM
Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC
CVSS 6.5
CVE-2026-66013 CRITICAL
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
CVE-2026-65710 HIGH
sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption
CVSS 7.1
CVE-2026-65709 HIGH
sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
CVSS 8.3
CVE-2026-65708 HIGH
sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController
CVSS 8.1
CVE-2026-17059 MEDIUM
Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter
CVSS 6.5
CVE-2026-13464 MEDIUM
Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
CVSS 5.3
CVE-2026-15630 CRITICAL
Casdoor < v3.115.0 - Authenticated Cross-Tenant Resource Manipulation via ID Parameter Mismatch
CVSS 9.9
CVE-2026-65699 MEDIUM
AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
CVSS 4.2
CVE-2026-47755 MEDIUM
ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal
CVSS 6.5
CVE-2026-47743 HIGH
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
CVSS 8.7
CVE-2026-65696 MEDIUM
Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API
CVSS 5.4
CVE-2026-65917 HIGH
CyberPanel IncBackups IDOR via Sequential Backup ID
CVSS 8.8
CVE-2026-65501 MEDIUM
WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-65463 MEDIUM
WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.4
CVE-2026-65456 MEDIUM
WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerability
CVSS 4.3
CVE-2026-61946 MEDIUM
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-3482 MEDIUM
IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
CVSS 5.3
CVE-2026-16624 CRITICAL
Cal.com Cal.diy < 6.2.0 - Authenticated Cross-Tenant Webhook Data Exposure via teamId Injection
CVSS 9.6
CVE-2026-65013 HIGH
Onlook tRPC Insecure Direct Object Reference via multiple procedures
CVSS 8.8
CVE-2026-65016 HIGH
n8n before 1.123.64 Privilege Escalation via SSO Instance-Role
CVSS 8.8
CVE-2026-2406 MEDIUM
IDOR in Universe Software's Online Registration and Workflow Management System
CVSS 6.5
CVE-2026-63259 MEDIUM
Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure
CVSS 4.3
Details
Vulnerabilities 2,100
Exploit Likelihood High