CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,777 vulnerabilities with CWE-639
CVE-2026-41949 MEDIUM
Dify v1.14.1 Authorization Bypass via File Preview Endpoint
CVSS 5.9
CVE-2026-41947 CRITICAL
Dify v1.14.1 Authorization Bypass via Trace Configuration Endpoints
CVSS 9.1
CVE-2026-8786 MEDIUM
Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
CVSS 6.3
CVE-2026-45666 MEDIUM
Open WebUI: Indirect Object Reference (IDOR) in user notes
CVSS 6.5
CVE-2026-44570 HIGH
Open WebUI: Inconsistent authorization controls within memories API
CVSS 8.3
CVE-2026-45402 HIGH
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
CVSS 8.1
CVE-2026-45398 HIGH
Open WebUI: IDOR - Retrieval API Bypasses Knowledge Base Access Controls
CVSS 7.5
CVE-2026-45386 MEDIUM
Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint
CVSS 4.3
CVE-2026-45385 MEDIUM
Open WebUI: An IDOR vulnerability exists in the update_message_by_id API endpoint
CVSS 4.3
CVE-2026-45671 HIGH
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
CVSS 8.0
CVE-2026-45349 HIGH
Open WebUI: Broken Access Control for Completions API
CVSS 7.1
CVE-2026-46408 HIGH
Vvveb: checkout IDOR allows unauthorized reuse of another user's cart
CVSS 7.6
CVE-2026-46407 HIGH
Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens
CVSS 8.1
CVE-2026-44718 MEDIUM
Mathesar: Missing collaborator checks allowed access to saved explorations in other databases
CVE-2026-44678 HIGH
Tuist: IDOR in preview deletion API allows cross-tenant deletion of any preview by UUID
CVE-2026-8629 HIGH
Crabbox < v0.12.0 Privilege Escalation via Agent Ticket Endpoints
CVSS 8.1
CVE-2026-44544 MEDIUM
gittuf: Policy can be rolled back to prior valid version
CVE-2026-42572 MEDIUM
Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`
CVSS 5.3
CVE-2026-44504 HIGH
Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-6008 MEDIUM
IDOR in Im Park's DijiDemi
CVSS 6.8
CVE-2026-5798 HIGH
Unsafe Object Reference (IDOR) vulnerability in Stel Order
CVE-2026-2347 CRITICAL
IDOR in Akıllı Ticaret's E-Commerce Pack
CVSS 9.8
CVE-2026-6206 MEDIUM
MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter
CVSS 5.3
CVE-2026-5395 HIGH
Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter
CVSS 8.2
CVE-2026-6063 MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
Details
Vulnerabilities 1,777
Exploit Likelihood High