CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,570 vulnerabilities with CWE-639
CVE-2026-31150 MEDIUM
Kaleris YMS 7.2.2.1 - Incorrect Access Control
CVSS 4.3
CVE-2026-4896 HIGH
WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation
CVSS 8.1
CVE-2026-25197 CRITICAL
Gardyn Cloud API Authorization Bypass Through User-Controlled Key
CVSS 9.1
CVE-2026-28736 MEDIUM
Focalboard IDOR in file content endpoint allows cross-user file access (unsupported product, no fix)
CVSS 4.3
CVE-2026-34832 MEDIUM
Scoold: Cross-Account Feedback Deletion (IDOR)
CVSS 6.5
CVE-2026-34584 MEDIUM
listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)
CVSS 5.4
CVE-2026-5326 MEDIUM
SourceCodester Leave Application System User Information index.php authorization
CVSS 5.3
CVE-2026-5246 MEDIUM
Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization
CVSS 5.6
CVE-2026-5199 LOW
Cross Namespace Access via Batch Operation
CVE-2026-3139 MEDIUM
User Profile Builder < 3.15.5 - IDOR
CVSS 4.3
CVE-2026-32976 MEDIUM
OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands
CVSS 6.5
CVE-2026-4400 MEDIUM
Multiple vulnerabilities in 1millionbot Millie chatbot
CVSS 6.5
CVE-2026-33030 HIGH
Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys
CVSS 8.8
CVE-2026-3321 HIGH
Authorization Bypass in ON24 Q&A chat
CVE-2026-3124 HIGH
Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'
CVSS 7.5
CVE-2026-33946 MEDIUM
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
CVSS 5.9
CVE-2026-34046 HIGH
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-31950 MEDIUM
LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats
CVSS 5.3
CVE-2026-4958 LOW
OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization
CVSS 3.1
CVE-2026-33764 MEDIUM
AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions
CVSS 4.3
CVE-2026-33759 MEDIUM
AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents
CVSS 5.3
CVE-2026-1496 CRITICAL
Coverity CLI Authentication Bypass
CVE-2026-33735 HIGH
MyTube has an Improper Access Control that Allows Complete Application Takeover
CVSS 8.8
CVE-2026-33730 MEDIUM
Open Source Point of Sale has an IDOR in Password Change (Home)
CVSS 6.5
CVE-2026-29071 LOW
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
CVSS 3.1
Details
Vulnerabilities 1,570
Exploit Likelihood High