CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,794 vulnerabilities with CWE-639
CVE-2025-58055 MEDIUM
Discourse < 3.5.1 - Authenticated Improper Access Control via AI Suggestion Endpoint Topic ID Manipulation
CVSS 4.3
CVE-2025-59687 MEDIUM
IMPAQTR Aurora <1.36 - Info Disclosure
CVSS 4.3
CVE-2025-56392 HIGH
Collegetivity 1.0.0 - Insecure Direct Object Reference via Dashboard Notes Endpoint
CVSS 8.1
CVE-2025-43827 MEDIUM
Liferay Portal 7.4.0-7.4.3.117 & DXP 2024.Q1.1-2024.Q1.5 - IDOR via Audit Event ID
CVSS 4.3
CVE-2025-41099 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 6.5
CVE-2025-41098 HIGH
BOLD Workplanner < 2.5.25 - Insecure Direct Object Reference via General Enquiry Web Service
CVSS 7.5
CVE-2025-41097 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2025-41096 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2025-41095 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2025-41094 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2025-41093 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2025-41092 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2025-41091 MEDIUM
BOLD Workplanner < 2.5.25 - Authenticated Insecure Direct Object Reference via Calendar Identifier
CVSS 4.3
CVE-2025-55795 LOW
openml/openml.org v2.0.20241110 - Open Redirect
CVSS 3.5
CVE-2025-10947 MEDIUM
Sistemas Pleno Gestão de Locação <2025.7.x - Auth Bypass
CVSS 5.3
CVE-2025-9342 MEDIUM
AHE Mobile 1.9.7-1.9.8 - Authorization Bypass Through User-Controlled Key
CVSS 6.5
CVE-2025-7106 MEDIUM
librechat < 0.7.9 - Improper Access Control in checkAccess Function
CVSS 5.3
CVE-2025-43810 MEDIUM
Liferay DXP 2023.Q3.1-2023.Q3.10 - Authenticated IDOR via Commerce Order Notes
CVSS 4.3
CVE-2025-59562 MEDIUM
Academy LMS <= 3.3.4 - Authorization Bypass Through User-Controlled Key
CVSS 5.5
CVE-2025-58012 LOW
Alex Content Mask <1.8.5.2 - Auth Bypass
CVSS 3.8
CVE-2025-57994 MEDIUM
Sayful Islam Upcoming Events Lists <1.4.0 - Auth Bypass
CVSS 5.4
CVE-2025-0875 MEDIUM
OBS (Student Affairs Information System) < v26.0328 - Authorization Bypass via Parameter Injection
CVSS 6.5
CVE-2025-10759 MEDIUM
Webkul QloApps < 1.7.0 - Authorization Bypass via CSRF Token Manipulation
CVSS 5.3
CVE-2025-9081 LOW
Mattermost <10.5.8, <9.11.17 - Info Disclosure
CVSS 3.1
CVE-2025-43803 MEDIUM
Liferay Digital Experience Platform - Insecure Direct Object Reference in Contacts Center Widget
CVSS 4.3
Details
Vulnerabilities 1,794
Exploit Likelihood High