CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,777 vulnerabilities with CWE-639
CVE-2026-5396 HIGH
Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter
CVSS 8.2
CVE-2026-3074 MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
CVE-2026-3073 MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
CVE-2026-1338 MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
CVE-2026-7648 MEDIUM
LearnPress <= 4.3.5 - Subscriber Payment Bypass
CVSS 4.3
CVE-2026-44426 MEDIUM
ShellHub: Cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
CVSS 6.5
CVE-2026-44424 MEDIUM
ShellHub: Cross-tenant IDOR in `GET /api/devices/:uid` discloses device data of any namespace
CVSS 6.5
CVE-2026-44423 MEDIUM
ShellHub: Cross-tenant IDOR in `GET /api/sessions/:uid` discloses SSH session data
CVSS 6.5
CVE-2026-42463 HIGH
SQLBot: Unauthorized Access Vulnerability
CVSS 8.1
CVE-2026-6965 MEDIUM
Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter
CVSS 5.3
CVE-2026-44341 MEDIUM
GoJobs: Insecure Direct Object Reference (IDOR) in Job Retrieval Endpoint
CVSS 5.3
CVE-2026-42889 CRITICAL
Relay Server WebSocket authentication bypass when token is omitted
CVSS 9.1
CVE-2026-29204 CRITICAL
WHMCS 7.4.0-18.12.1, 18.13.0-18.13.2, 9.0.0-9.0.3 - Authorization Bypass via clientarea.php addonId
CVSS 9.1
CVE-2026-6001 HIGH
IDOR in Abis Technology's BAPSİS
CVSS 8.8
CVE-2026-43890 HIGH
Outline: IDOR in subscriptions.create allows cross-tenant subscription on private documents (sibling of GHSA-23jj-rp48-w7q7)
CVSS 7.7
CVE-2026-43883 MEDIUM
WWBN AVideo: IDOR in PayPalYPT agreementCancel.json.php Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements
CVSS 4.2
CVE-2026-38568 HIGH
HireFlow v1.2 - Privilege Escalation
CVSS 8.1
CVE-2026-33356 HIGH
Meari MQTT broker missing per-device subscribe ACL
CVSS 7.7
CVE-2026-42609 HIGH
Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
CVSS 8.1
CVE-2026-8196 LOW
JeecgBoot mLogin Endpoint LoginController.java authorization
CVSS 3.7
CVE-2026-42456 MEDIUM
AnythingLLM: Cross-User TTS Audio Disclosure via Chat ID (IDOR)
CVSS 4.3
CVE-2026-42291 MEDIUM
SysReptor: Read-write access to personal notes by sharing-link creation with no authorization in SysReptor Professional
CVSS 6.8
CVE-2026-42205 HIGH
Avo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources
CVSS 8.8
CVE-2026-44400 HIGH
MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdmin
CVSS 8.1
CVE-2026-42279 MEDIUM
solidtime: Time entry update endpoint allows cross-organization modification of a known time-entry UUID
CVSS 5.8
Details
Vulnerabilities 1,777
Exploit Likelihood High