CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,101 vulnerabilities with CWE-639
CVE-2026-47198 HIGH
Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVSS 8.5
CVE-2026-47130 HIGH
NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering
CVSS 7.1
CVE-2026-44585 MEDIUM
Paymenter: Broken object level authorization via service reference manipulation on ticket creation
CVSS 5.4
CVE-2026-13381 HIGH
VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion
CVE-2026-45295 MEDIUM
FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVSS 6.5
CVE-2026-63763 HIGH
SurrealDB before 2.5.0 Privilege Escalation via Future Fields
CVSS 8.8
CVE-2026-63745 MEDIUM
SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id
CVSS 5.4
CVE-2026-63735 HIGH
SurrealDB before 3.2.0 Authentication Bypass via Custom API
CVSS 8.1
CVE-2026-16217 MEDIUM
guohongze adminset Delivery Deployment Endpoint deli.py authorization
CVSS 6.3
CVE-2026-16214 MEDIUM
geex-arts django-jet Dashboard views.py authorization
CVSS 6.3
CVE-2026-16075 MEDIUM
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
CVSS 4.3
CVE-2026-55518 CRITICAL
Avo < 3.32.1 and 4.0.0-beta.51 - Association Authorization Bypass
CVSS 9.6
CVE-2026-13445 HIGH
IBM Langflow OSS 1.0.0-1.10.1 - Cross-User File Access
CVSS 8.1
CVE-2026-48016 MEDIUM
Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment
CVSS 4.3
CVE-2026-63307 MEDIUM
Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource
CVSS 6.5
CVE-2026-12693 CRITICAL
IDOR in Vimesoft's Enterprise Video Platform
CVSS 9.4
CVE-2026-11763 MEDIUM
IDOR in GIS Informatics' GisLab Laboratory Management System
CVSS 6.5
CVE-2026-63099 MEDIUM
TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
CVSS 6.5
CVE-2026-63095 MEDIUM
Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
CVSS 6.5
CVE-2026-22104 HIGH
Improper access control in Hashtopolis server chunk activity component
CVE-2026-12393 MEDIUM
WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR
CVSS 5.4
CVE-2026-11966 MEDIUM
User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
CVSS 5.3
CVE-2026-15159 MEDIUM
Ninja Forms Excel Export <= 3.3.6 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-62233 HIGH
grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVSS 8.8
CVE-2026-43977 HIGH
wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
CVSS 7.5
Details
Vulnerabilities 2,101
Exploit Likelihood High