CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,100 vulnerabilities with CWE-639
CVE-2026-65316 MEDIUM
Xuxueli Xxl-job < 2.4.2 - IDOR
CVSS 6.5
CVE-2026-56147 HIGH
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise
CVSS 7.1
CVE-2026-47419 HIGH
PraisonAI Platform < 0.1.4 Agent Endpoints - Insecure Direct Object Reference
CVSS 8.3
CVE-2026-47418 HIGH
PraisonAI Platform < 0.1.4 Project Endpoints - Insecure Direct Object Reference
CVSS 8.1
CVE-2026-47417 HIGH
PraisonAI Platform < 0.1.4 Comment Endpoints - Insecure Direct Object Reference
CVSS 8.1
CVE-2026-47415 HIGH
PraisonAI Platform < 0.1.4 Issue Endpoints - Insecure Direct Object Reference
CVSS 8.3
CVE-2026-47414 HIGH
PraisonAI Platform < 0.1.4 Label Endpoints - Insecure Direct Object Reference
CVSS 7.6
CVE-2026-47408 MEDIUM
praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
CVSS 6.5
CVE-2026-47407 CRITICAL
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
CVE-2026-47406 HIGH
PraisonAI Platform < 0.1.4 Dependency Endpoints - Insecure Direct Object Reference
CVSS 8.1
CVE-2026-47399 HIGH
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
CVSS 8.8
CVE-2026-15342 MEDIUM
Plane < 1.3.0 - Authenticated Cross-Tenant Data Exposure and Deletion via Asset-Management API
CVSS 6.5
CVE-2026-28317 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-28316 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-28314 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-28313 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-28308 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-28305 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-28302 CRITICAL
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVSS 9.1
CVE-2026-16450 MEDIUM
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
CVSS 4.3
CVE-2026-14184 MEDIUM
Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR
CVSS 5.4
CVE-2026-14183 MEDIUM
Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR
CVSS 4.3
CVE-2026-57494 HIGH
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
CVE-2026-55544 HIGH
NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering
CVSS 7.6
CVE-2026-47198 HIGH
Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVSS 8.5
Details
Vulnerabilities 2,100
Exploit Likelihood High