CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,101 vulnerabilities with CWE-639
CVE-2026-15058 LOW
Devolutions Server - Authorization Bypass Through User-Controlled Key
CVSS 3.1
CVE-2026-52841 LOW
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
CVSS 3.1
CVE-2026-52839 LOW
Easy!Appointments < 1.6.0 - Cross-Provider Appointment Authorization Bypass
CVSS 3.3
CVE-2026-52837 MEDIUM
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
CVE-2026-9341 MEDIUM
Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
CVSS 4.3
CVE-2026-15389 HIGH
Inadequate access control in Sesame Time session management
CVE-2026-15622 MEDIUM
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
CVSS 5.3
CVE-2026-58410 HIGH
ChurchCRM < 7.4.0 - Authenticated Family Record Access Control Bypass
CVSS 7.1
CVE-2026-6541 MEDIUM
Mattermost - Unscoped Updates to Other Playbooks' Metric Configuration
CVSS 4.3
CVE-2026-61971 LOW
WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability
CVSS 2.7
CVE-2026-57694 MEDIUM
WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-9708 MEDIUM
Mattermost - Incoming Webhook User Attribution via Unvalidated Webhook Owner
CVSS 4.9
CVE-2026-10103 MEDIUM
Mattermost 10.11/11.6/11.7 - Shared Channel Post Ownership Bypass
CVSS 4.3
CVE-2026-14165 HIGH
Tuleap Enterprise Edition 17.0-17.5 - Unauthorized Data Access
CVSS 7.5
CVE-2026-15516 MEDIUM
MacCMS Pro Installation Index.php step5 authorization
CVSS 5.6
CVE-2026-10041 MEDIUM
WCFM Frontend Manager for WooCommerce <= 6.7.27 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2026-13116 MEDIUM
WooCommerce PDF Invoices & Packing Slips <= 5.14.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-55881 HIGH
OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint
CVE-2026-55880 HIGH
OpenReplay: Cross-user IDOR in notes and dashboard widgets
CVSS 7.1
CVE-2026-55515 MEDIUM
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
CVSS 5.0
CVE-2026-6212 HIGH
IDOR in Teracity's TeraMIS
CVSS 8.8
CVE-2026-61460 HIGH
Krayin CRM Insecure Direct Object Reference via Controllers
CVSS 8.8
CVE-2026-55516 HIGH
Snipe-IT: Cross-company asset maintenance re-parenting via API update
CVSS 7.7
CVE-2026-55478 MEDIUM
Snipe-IT: Missing object-level authorization in Kits API
CVSS 5.4
CVE-2026-55670 LOW
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
Details
Vulnerabilities 2,101
Exploit Likelihood High