CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,101 vulnerabilities with CWE-639
CVE-2026-15058
LOW
Devolutions Server - Authorization Bypass Through User-Controlled Key
CVSS 3.1
CVE-2026-52841
LOW
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
CVSS 3.1
CVE-2026-52839
LOW
Easy!Appointments < 1.6.0 - Cross-Provider Appointment Authorization Bypass
CVSS 3.3
CVE-2026-52837
MEDIUM
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
CVE-2026-9341
MEDIUM
Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
CVSS 4.3
CVE-2026-15389
HIGH
Inadequate access control in Sesame Time session management
CVE-2026-15622
MEDIUM
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
CVSS 5.3
CVE-2026-58410
HIGH
ChurchCRM < 7.4.0 - Authenticated Family Record Access Control Bypass
CVSS 7.1
CVE-2026-6541
MEDIUM
Mattermost - Unscoped Updates to Other Playbooks' Metric Configuration
CVSS 4.3
CVE-2026-61971
LOW
WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability
CVSS 2.7
CVE-2026-57694
MEDIUM
WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-9708
MEDIUM
Mattermost - Incoming Webhook User Attribution via Unvalidated Webhook Owner
CVSS 4.9
CVE-2026-10103
MEDIUM
Mattermost 10.11/11.6/11.7 - Shared Channel Post Ownership Bypass
CVSS 4.3
CVE-2026-14165
HIGH
Tuleap Enterprise Edition 17.0-17.5 - Unauthorized Data Access
CVSS 7.5
CVE-2026-15516
MEDIUM
MacCMS Pro Installation Index.php step5 authorization
CVSS 5.6
CVE-2026-10041
MEDIUM
WCFM Frontend Manager for WooCommerce <= 6.7.27 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2026-13116
MEDIUM
WooCommerce PDF Invoices & Packing Slips <= 5.14.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-55881
HIGH
OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint
CVE-2026-55880
HIGH
OpenReplay: Cross-user IDOR in notes and dashboard widgets
CVSS 7.1
CVE-2026-55515
MEDIUM
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
CVSS 5.0
CVE-2026-6212
HIGH
IDOR in Teracity's TeraMIS
CVSS 8.8
CVE-2026-61460
HIGH
Krayin CRM Insecure Direct Object Reference via Controllers
CVSS 8.8
CVE-2026-55516
HIGH
Snipe-IT: Cross-company asset maintenance re-parenting via API update
CVSS 7.7
CVE-2026-55478
MEDIUM
Snipe-IT: Missing object-level authorization in Kits API
CVSS 5.4
CVE-2026-55670
LOW
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
Details
Vulnerabilities
2,101
Exploit Likelihood
High