CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,101 vulnerabilities with CWE-639
CVE-2026-59190
HIGH
Grav Admin Plugin — IDOR Privilege Escalation via saveUser()
CVE-2026-2398
HIGH
IDOR in AdamPOS' MobilMen 20T
CVSS 8.8
CVE-2026-56765
CRITICAL
Vikunja < 2.2.1 - Link Share Disclosure and Attachment IDOR
CVSS 9.8
CVE-2026-41878
HIGH
Insecure Direct Object Reference in R-SOFT DMS
CVE-2026-6802
MEDIUM
Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter
CVSS 5.3
CVE-2026-12400
MEDIUM
WordPress FlowForms <= 1.1.1 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2026-55604
HIGH
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
CVSS 8.6
CVE-2026-51925
HIGH
docuForm Client 11.11c - Remote Code Execution via Local File Inclusion in dfm-menu_report.php
CVSS 8.1
CVE-2026-51924
HIGH
docuForm Client 11.11c - Remote Code Execution via File Upload and Report.php Component
CVSS 8.1
CVE-2026-51923
HIGH
docuForm Client 11.11c - Insecure Direct Object Reference and Remote Code Execution via User Settings Component
CVSS 8.1
CVE-2026-59817
MEDIUM
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVSS 5.3
CVE-2026-59216
HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-59215
LOW
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
CVSS 3.1
CVE-2026-15191
MEDIUM
mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
CVSS 6.3
CVE-2026-1989
HIGH
IDOR in PAVO Inc.'s PAVO Pay
CVSS 7.5
CVE-2026-12433
MEDIUM
Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter
CVSS 4.3
CVE-2026-13450
MEDIUM
GamiPress <= 7.9.4 - Unauthenticated Activity Log Exposure
CVSS 5.3
CVE-2026-12418
MEDIUM
User Frontend <= 4.3.7 - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-5523
HIGH
Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form
CVSS 8.8
CVE-2026-54590
MEDIUM
AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
CVSS 5.9
CVE-2026-35210
HIGH
OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
CVSS 7.1
CVE-2026-60104
HIGH
Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
CVSS 8.7
CVE-2026-15036
MEDIUM
Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
CVSS 4.3
CVE-2026-59253
MEDIUM
n8n - Improper Authorization in Workflow Assignment to Folders
CVSS 5.0
CVE-2026-5459
MEDIUM
WordPress User Frontend <= 4.3.1 - Insecure Direct Object Reference
CVSS 5.3
Details
Vulnerabilities
2,101
Exploit Likelihood
High