CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,101 vulnerabilities with CWE-639
CVE-2026-47198
HIGH
Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVSS 8.5
CVE-2026-47130
HIGH
NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering
CVSS 7.1
CVE-2026-44585
MEDIUM
Paymenter: Broken object level authorization via service reference manipulation on ticket creation
CVSS 5.4
CVE-2026-13381
HIGH
VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion
CVE-2026-45295
MEDIUM
FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVSS 6.5
CVE-2026-63763
HIGH
SurrealDB before 2.5.0 Privilege Escalation via Future Fields
CVSS 8.8
CVE-2026-63745
MEDIUM
SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id
CVSS 5.4
CVE-2026-63735
HIGH
SurrealDB before 3.2.0 Authentication Bypass via Custom API
CVSS 8.1
CVE-2026-16217
MEDIUM
guohongze adminset Delivery Deployment Endpoint deli.py authorization
CVSS 6.3
CVE-2026-16214
MEDIUM
geex-arts django-jet Dashboard views.py authorization
CVSS 6.3
CVE-2026-16075
MEDIUM
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
CVSS 4.3
CVE-2026-55518
CRITICAL
Avo < 3.32.1 and 4.0.0-beta.51 - Association Authorization Bypass
CVSS 9.6
CVE-2026-13445
HIGH
IBM Langflow OSS 1.0.0-1.10.1 - Cross-User File Access
CVSS 8.1
CVE-2026-48016
MEDIUM
Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment
CVSS 4.3
CVE-2026-63307
MEDIUM
Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource
CVSS 6.5
CVE-2026-12693
CRITICAL
IDOR in Vimesoft's Enterprise Video Platform
CVSS 9.4
CVE-2026-11763
MEDIUM
IDOR in GIS Informatics' GisLab Laboratory Management System
CVSS 6.5
CVE-2026-63099
MEDIUM
TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
CVSS 6.5
CVE-2026-63095
MEDIUM
Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
CVSS 6.5
CVE-2026-22104
HIGH
Improper access control in Hashtopolis server chunk activity component
CVE-2026-12393
MEDIUM
WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR
CVSS 5.4
CVE-2026-11966
MEDIUM
User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
CVSS 5.3
CVE-2026-15159
MEDIUM
Ninja Forms Excel Export <= 3.3.6 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-62233
HIGH
grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVSS 8.8
CVE-2026-43977
HIGH
wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
CVSS 7.5
Details
Vulnerabilities
2,101
Exploit Likelihood
High