CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,101 vulnerabilities with CWE-639
CVE-2026-59190 HIGH
Grav Admin Plugin — IDOR Privilege Escalation via saveUser()
CVE-2026-2398 HIGH
IDOR in AdamPOS' MobilMen 20T
CVSS 8.8
CVE-2026-56765 CRITICAL
Vikunja < 2.2.1 - Link Share Disclosure and Attachment IDOR
CVSS 9.8
CVE-2026-41878 HIGH
Insecure Direct Object Reference in R-SOFT DMS
CVE-2026-6802 MEDIUM
Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter
CVSS 5.3
CVE-2026-12400 MEDIUM
WordPress FlowForms <= 1.1.1 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2026-55604 HIGH
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
CVSS 8.6
CVE-2026-51925 HIGH
docuForm Client 11.11c - Remote Code Execution via Local File Inclusion in dfm-menu_report.php
CVSS 8.1
CVE-2026-51924 HIGH
docuForm Client 11.11c - Remote Code Execution via File Upload and Report.php Component
CVSS 8.1
CVE-2026-51923 HIGH
docuForm Client 11.11c - Insecure Direct Object Reference and Remote Code Execution via User Settings Component
CVSS 8.1
CVE-2026-59817 MEDIUM
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVSS 5.3
CVE-2026-59216 HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-59215 LOW
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
CVSS 3.1
CVE-2026-15191 MEDIUM
mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
CVSS 6.3
CVE-2026-1989 HIGH
IDOR in PAVO Inc.'s PAVO Pay
CVSS 7.5
CVE-2026-12433 MEDIUM
Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter
CVSS 4.3
CVE-2026-13450 MEDIUM
GamiPress <= 7.9.4 - Unauthenticated Activity Log Exposure
CVSS 5.3
CVE-2026-12418 MEDIUM
User Frontend <= 4.3.7 - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-5523 HIGH
Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form
CVSS 8.8
CVE-2026-54590 MEDIUM
AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
CVSS 5.9
CVE-2026-35210 HIGH
OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
CVSS 7.1
CVE-2026-60104 HIGH
Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
CVSS 8.7
CVE-2026-15036 MEDIUM
Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
CVSS 4.3
CVE-2026-59253 MEDIUM
n8n - Improper Authorization in Workflow Assignment to Folders
CVSS 5.0
CVE-2026-5459 MEDIUM
WordPress User Frontend <= 4.3.1 - Insecure Direct Object Reference
CVSS 5.3
Details
Vulnerabilities 2,101
Exploit Likelihood High