CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,570 vulnerabilities with CWE-639
CVE-2026-3568 MEDIUM
MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update
CVSS 4.3
CVE-2026-2104 MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
CVE-2026-5875 MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-35478 HIGH
InvenTree has Arbitrary API Token Creation
CVSS 8.3
CVE-2026-35165 MEDIUM
LORIS has incorrect access checks in document_repository
CVSS 6.3
CVE-2026-34985 MEDIUM
LORIS has incorrect access checks in media module
CVSS 6.3
CVE-2026-32589 HIGH
Mirror-registry: quay: insecure direct object reference in blobupload
CVSS 7.4
CVE-2026-35023 MEDIUM
Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.php
CVSS 4.3
CVE-2026-39616 MEDIUM
WordPress Download Attachments plugin <= 1.4.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-39526 MEDIUM
WordPress WpStream plugin < 4.11.2 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.4
CVE-2026-39510 LOW
WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Insecure Direct Object References (IDOR) vulnerability
CVSS 2.7
CVE-2026-4654 MEDIUM
Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter
CVSS 5.3
CVE-2026-4330 MEDIUM
Blog2Social: Social Media Auto Post & Scheduler < 8.8.3 - Authorization Bypass
CVSS 4.3
CVE-2026-5167 MEDIUM
Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint
CVSS 5.3
CVE-2026-39374 MEDIUM
Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint
CVSS 6.5
CVE-2026-39354 MEDIUM
Scoold has an Authenticated Arbitrary Question Overwrite via Client-Controlled postId in POST /questions/ask
CVSS 6.5
CVE-2026-39331 HIGH
ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families
CVSS 8.1
CVE-2026-39384 HIGH
FreeScout Customer Merge Cross-Mailbox Authorization Bypass
CVSS 7.6
CVE-2026-35584 MEDIUM
FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration
CVSS 6.5
CVE-2026-35489 HIGH
Tandoor Recipes — `amount`/`unit` bypass serializer in `food/{id}/shopping/`
CVSS 7.3
CVE-2026-5465 HIGH
Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter
CVSS 8.8
CVE-2026-35183 HIGH
Brave CMS has an Insecure Direct Object Reference in Article Image Deletion
CVSS 7.1
CVE-2026-35173 MEDIUM
Chyrp Lite has an IDOR via Mass Assignment in Post Model
CVSS 6.5
CVE-2026-35045 HIGH
Tandoor Recipes Affected by Private Recipe Exposure and Unauthorized Modification
CVSS 8.1
CVE-2026-34444 HIGH
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
Details
Vulnerabilities 1,570
Exploit Likelihood High