CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,571 vulnerabilities with CWE-639
CVE-2026-33297
CRITICAL
AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php
CVSS 9.1
CVE-2026-4563
MEDIUM
MacCMS Member Order Detail User.php order_info authorization
CVSS 4.3
CVE-2026-4549
LOW
mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization
CVSS 3.1
CVE-2026-33425
MEDIUM
Discourse has inferable private group membership or existence via exclude_groups parameter
CVSS 5.3
CVE-2026-33053
HIGH
Langflow has Missing Ownership Verification in API Key Deletion (IDOR)
CVSS 8.8
CVE-2026-32114
MEDIUM
Discourse's unscoped status lookups leak restricted metadata
CVSS 4.3
CVE-2026-31869
MEDIUM
Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check
CVSS 4.3
CVE-2026-32761
MEDIUM
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
CVSS 6.5
CVE-2026-32697
MEDIUM
SuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authenticated user to read any record (IDOR)
CVSS 6.5
CVE-2026-29189
HIGH
SuiteCRM has a REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship Endpoints
CVSS 8.1
CVE-2026-32039
MEDIUM
OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender
CVSS 5.9
CVE-2026-33304
MEDIUM
OpenEMR has Authorization Bypass in Dated Reminders Log
CVSS 6.5
CVE-2026-25744
MEDIUM
OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals
CVSS 6.5
CVE-2026-32867
MEDIUM
OPEXUS eComplaint unauthenticated file upload
CVSS 5.4
CVE-2026-27397
MEDIUM
WordPress Really Simple Security Pro plugin <= 9.5.4.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-32638
LOW
StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
CVSS 2.7
CVE-2026-25745
MEDIUM
OpenEMR's Message Update Ignores Patient id
CVSS 6.5
CVE-2026-32694
MEDIUM
Insecure Direct Object Reference attack via predictable secret ID in Juju
CVSS 6.6
CVE-2026-30884
CRITICAL
mdjnelson/moodle-mod_customcert Vulnerable to Authorization Bypass Through User-Controlled Key
CVSS 9.6
CVE-2026-26004
MEDIUM
Sentry allows unauthorized access to event data across organizational boundaries
CVE-2026-24901
HIGH
Outline's IDOR allows unauthorized viewing and seizing of private deleted drafts
CVSS 8.1
CVE-2026-4208
HIGH
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
CVSS 8.8
CVE-2026-4171
MEDIUM
CodeGenieApp serverless-express API Endpoint TodoList.ts authorization
CVSS 6.3
CVE-2026-3020
HIGH
Identity based authorization bypass vulnerability (IDOR) in the Wakyma application web
CVE-2026-2461
MEDIUM
Missing authorization check allows unauthorized modification of other users' comments on a board
CVSS 4.3
Details
Vulnerabilities
1,571
Exploit Likelihood
High