CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,101 vulnerabilities with CWE-639
CVE-2026-11889 MEDIUM
SALTO ProAccess Space Authorization Bypass Through User-Controlled Key
CVSS 6.5
CVE-2026-53536 MEDIUM
Activepieces: Cross-tenant file download via missing JWT audience check on step-files signed URL
CVE-2026-15945 MEDIUM
Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2
CVSS 4.3
CVE-2026-57205 MEDIUM
SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints
CVSS 4.3
CVE-2026-54568 MEDIUM
Microsoft UFO 3.0.0 to < 3.0.6 - Device Info Authorization Bypass
CVSS 4.3
CVE-2026-59237 MEDIUM
IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders
CVE-2026-35147 HIGH
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.
CVSS 8.2
CVE-2026-12906 LOW
RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
CVSS 2.7
CVE-2026-12510 MEDIUM
AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
CVSS 5.9
CVE-2026-15909 MEDIUM
RafyMrX TOKO-ONLINE-ROTI add.php authorization
CVSS 6.3
CVE-2026-55234 HIGH
Wekan < 9.37 Cards/Lists/Swimlanes - Cross-Board Write Access Control Bypass
CVSS 8.5
CVE-2026-53447 MEDIUM
Wekan < 9.35 cloneBoard - Private Board Information Disclosure
CVSS 6.5
CVE-2026-54052 CRITICAL
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVSS 9.9
CVE-2026-52869 HIGH
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVSS 7.1
CVE-2026-58660 HIGH
Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop
CVSS 8.1
CVE-2026-48799 HIGH
Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
CVSS 7.7
CVE-2026-44986 CRITICAL
Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
CVSS 9.9
CVE-2026-61836 HIGH
Directus: Authorization-dependent response served from unsegmented cache key
CVSS 8.6
CVE-2026-59259 MEDIUM
n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
CVSS 6.5
CVE-2026-59254 MEDIUM
n8n - External Secrets Disclosure via Workflow Node Expressions
CVE-2026-59236 MEDIUM
Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection
CVE-2026-59235 HIGH
Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts
CVE-2026-11580 MEDIUM
Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
CVSS 5.5
CVE-2026-59733 HIGH
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
CVSS 8.8
CVE-2026-15637 HIGH
Devolutions Server - Authorization Bypass Through User-Controlled Key
CVSS 7.5
Details
Vulnerabilities 2,101
Exploit Likelihood High