CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,571 vulnerabilities with CWE-639
CVE-2026-33297 CRITICAL
AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php
CVSS 9.1
CVE-2026-4563 MEDIUM
MacCMS Member Order Detail User.php order_info authorization
CVSS 4.3
CVE-2026-4549 LOW
mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization
CVSS 3.1
CVE-2026-33425 MEDIUM
Discourse has inferable private group membership or existence via exclude_groups parameter
CVSS 5.3
CVE-2026-33053 HIGH
Langflow has Missing Ownership Verification in API Key Deletion (IDOR)
CVSS 8.8
CVE-2026-32114 MEDIUM
Discourse's unscoped status lookups leak restricted metadata
CVSS 4.3
CVE-2026-31869 MEDIUM
Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check
CVSS 4.3
CVE-2026-32761 MEDIUM
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
CVSS 6.5
CVE-2026-32697 MEDIUM
SuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authenticated user to read any record (IDOR)
CVSS 6.5
CVE-2026-29189 HIGH
SuiteCRM has a REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship Endpoints
CVSS 8.1
CVE-2026-32039 MEDIUM
OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender
CVSS 5.9
CVE-2026-33304 MEDIUM
OpenEMR has Authorization Bypass in Dated Reminders Log
CVSS 6.5
CVE-2026-25744 MEDIUM
OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals
CVSS 6.5
CVE-2026-32867 MEDIUM
OPEXUS eComplaint unauthenticated file upload
CVSS 5.4
CVE-2026-27397 MEDIUM
WordPress Really Simple Security Pro plugin <= 9.5.4.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-32638 LOW
StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
CVSS 2.7
CVE-2026-25745 MEDIUM
OpenEMR's Message Update Ignores Patient id
CVSS 6.5
CVE-2026-32694 MEDIUM
Insecure Direct Object Reference attack via predictable secret ID in Juju
CVSS 6.6
CVE-2026-30884 CRITICAL
mdjnelson/moodle-mod_customcert Vulnerable to Authorization Bypass Through User-Controlled Key
CVSS 9.6
CVE-2026-26004 MEDIUM
Sentry allows unauthorized access to event data across organizational boundaries
CVE-2026-24901 HIGH
Outline's IDOR allows unauthorized viewing and seizing of private deleted drafts
CVSS 8.1
CVE-2026-4208 HIGH
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
CVSS 8.8
CVE-2026-4171 MEDIUM
CodeGenieApp serverless-express API Endpoint TodoList.ts authorization
CVSS 6.3
CVE-2026-3020 HIGH
Identity based authorization bypass vulnerability (IDOR) in the Wakyma application web
CVE-2026-2461 MEDIUM
Missing authorization check allows unauthorized modification of other users' comments on a board
CVSS 4.3
Details
Vulnerabilities 1,571
Exploit Likelihood High