CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,777 vulnerabilities with CWE-639
CVE-2026-41949
MEDIUM
Dify v1.14.1 Authorization Bypass via File Preview Endpoint
CVSS 5.9
CVE-2026-41947
CRITICAL
Dify v1.14.1 Authorization Bypass via Trace Configuration Endpoints
CVSS 9.1
CVE-2026-8786
MEDIUM
Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
CVSS 6.3
CVE-2026-45666
MEDIUM
Open WebUI: Indirect Object Reference (IDOR) in user notes
CVSS 6.5
CVE-2026-44570
HIGH
Open WebUI: Inconsistent authorization controls within memories API
CVSS 8.3
CVE-2026-45402
HIGH
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
CVSS 8.1
CVE-2026-45398
HIGH
Open WebUI: IDOR - Retrieval API Bypasses Knowledge Base Access Controls
CVSS 7.5
CVE-2026-45386
MEDIUM
Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint
CVSS 4.3
CVE-2026-45385
MEDIUM
Open WebUI: An IDOR vulnerability exists in the update_message_by_id API endpoint
CVSS 4.3
CVE-2026-45671
HIGH
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
CVSS 8.0
CVE-2026-45349
HIGH
Open WebUI: Broken Access Control for Completions API
CVSS 7.1
CVE-2026-46408
HIGH
Vvveb: checkout IDOR allows unauthorized reuse of another user's cart
CVSS 7.6
CVE-2026-46407
HIGH
Vvveb: admin/auth-token IDOR allows unauthorized disclosure of administrator REST API tokens
CVSS 8.1
CVE-2026-44718
MEDIUM
Mathesar: Missing collaborator checks allowed access to saved explorations in other databases
CVE-2026-44678
HIGH
Tuist: IDOR in preview deletion API allows cross-tenant deletion of any preview by UUID
CVE-2026-8629
HIGH
Crabbox < v0.12.0 Privilege Escalation via Agent Ticket Endpoints
CVSS 8.1
CVE-2026-44544
MEDIUM
gittuf: Policy can be rolled back to prior valid version
CVE-2026-42572
MEDIUM
Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`
CVSS 5.3
CVE-2026-44504
HIGH
Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-6008
MEDIUM
IDOR in Im Park's DijiDemi
CVSS 6.8
CVE-2026-5798
HIGH
Unsafe Object Reference (IDOR) vulnerability in Stel Order
CVE-2026-2347
CRITICAL
IDOR in Akıllı Ticaret's E-Commerce Pack
CVSS 9.8
CVE-2026-6206
MEDIUM
MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter
CVSS 5.3
CVE-2026-5395
HIGH
Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter
CVSS 8.2
CVE-2026-6063
MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
Details
Vulnerabilities
1,777
Exploit Likelihood
High