CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,570 vulnerabilities with CWE-639
CVE-2026-5845 CRITICAL
Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server
CVSS 9.6
CVE-2026-3307 LOW
Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
CVSS 2.7
CVE-2026-40907 MEDIUM
WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens
CVSS 6.5
CVE-2026-40867 HIGH
Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
CVE-2026-40866 HIGH
Horilla: Unauthorized Document Overwrite via File Upload Endpoint
CVE-2026-40865 HIGH
Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
CVE-2026-5652 CRITICAL
Authorization Bypass Through User-Controlled Key in Crafty Controller
CVSS 9.0
CVE-2026-40591 HIGH
FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Customer Modification
CVSS 7.1
CVE-2026-40590 MEDIUM
FreeScout's Customer AJAX Create Modifies Hidden Existing Customer
CVSS 4.3
CVE-2026-40589 HIGH
FreeScout has Customer Edit Cross-Mailbox Email Takeover
CVSS 7.6
CVE-2026-40570 MEDIUM
FreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Full Customer PII
CVE-2026-39386 HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-40896 MEDIUM
OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup
CVSS 6.5
CVE-2026-6614 MEDIUM
TransformerOptimus SuperAGI project.py get_projects_organisation authorization
CVSS 6.3
CVE-2026-6613 MEDIUM
TransformerOptimus SuperAGI agent.py get_schedule_data authorization
CVSS 6.3
CVE-2026-6612 MEDIUM
TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization
CVSS 6.3
CVE-2026-6586 MEDIUM
TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization
CVSS 6.3
CVE-2026-6585 MEDIUM
TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization
CVSS 5.4
CVE-2026-6584 MEDIUM
TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization
CVSS 5.4
CVE-2026-6583 MEDIUM
TransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization
CVSS 5.4
CVE-2026-6571 MEDIUM
kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
CVSS 6.3
CVE-2026-6570 LOW
kodcloud KodExplorer systemMember.class.php initInstall authorization
CVSS 2.7
CVE-2026-40480 HIGH
ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`
CVE-2026-5234 MEDIUM
LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
CVSS 5.3
CVE-2026-40308 HIGH
My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog
Details
Vulnerabilities 1,570
Exploit Likelihood High