CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,101 vulnerabilities with CWE-639
CVE-2026-3688
HIGH
WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
CVSS 8.1
CVE-2026-55429
HIGH
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
CVSS 8.7
CVE-2026-55418
HIGH
FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)
CVSS 8.6
CVE-2026-54602
HIGH
FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord
CVE-2026-53729
HIGH
DataEase ExportCenter IDOR allows cross-user export task access
CVE-2026-50530
HIGH
DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets
CVE-2026-49296
MEDIUM
Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}
CVSS 6.5
CVE-2026-5799
HIGH
IDOR in Idvlabs' Ontime
CVSS 7.5
CVE-2026-5730
HIGH
IDOR in Idvlabs' Ontime
CVSS 7.5
CVE-2026-57870
MEDIUM
MicroRealEstate < 1.0.0-alpha3 - Authorization Bypass Through User-Controlled Key
CVE-2026-57869
HIGH
MicroRealEstate < 1.0.0-alpha3 - Use of Predictable Algorithm in Random Number Generator
CVE-2026-57868
HIGH
MicroRealEstate < 1.0.0-alpha3 - Authorization Bypass Through User-Controlled Key
CVE-2026-34044
HIGH
Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped)
CVSS 7.7
CVE-2026-34037
CRITICAL
Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()
CVSS 9.9
CVE-2026-53644
HIGH
FOSSBilling 0.5.3-0.7.2 Serviceapikey - API Key Secret Exposure
CVE-2026-53643
HIGH
FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
CVE-2026-34167
MEDIUM
Coolify: Cross-tenant activity log disclosure via unlocked Livewire property in ActivityMonitor
CVSS 5.0
CVE-2026-59712
HIGH
Leantime - Credential Disclosure via Unauthenticated JSON-RPC users.getUser Method
CVSS 8.1
CVE-2026-12686
CRITICAL
Incorrect authorisation in Adiss’s Biloop
CVE-2026-49099
MEDIUM
Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
CVSS 5.3
CVE-2026-48206
MEDIUM
Apache Camel Jira 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-46585
HIGH
Apache Camel Lucene 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 7.5
CVE-2026-46453
MEDIUM
Apache Camel 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-14793
MEDIUM
Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
CVSS 4.3
CVE-2026-14753
HIGH
mjperpinosa stumasy Note Handler/Assignment notes authorization
CVSS 7.3
Details
Vulnerabilities
2,101
Exploit Likelihood
High