CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,101 vulnerabilities with CWE-639
CVE-2026-3688 HIGH
WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
CVSS 8.1
CVE-2026-55429 HIGH
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
CVSS 8.7
CVE-2026-55418 HIGH
FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)
CVSS 8.6
CVE-2026-54602 HIGH
FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord
CVE-2026-53729 HIGH
DataEase ExportCenter IDOR allows cross-user export task access
CVE-2026-50530 HIGH
DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets
CVE-2026-49296 MEDIUM
Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}
CVSS 6.5
CVE-2026-5799 HIGH
IDOR in Idvlabs' Ontime
CVSS 7.5
CVE-2026-5730 HIGH
IDOR in Idvlabs' Ontime
CVSS 7.5
CVE-2026-57870 MEDIUM
MicroRealEstate < 1.0.0-alpha3 - Authorization Bypass Through User-Controlled Key
CVE-2026-57869 HIGH
MicroRealEstate < 1.0.0-alpha3 - Use of Predictable Algorithm in Random Number Generator
CVE-2026-57868 HIGH
MicroRealEstate < 1.0.0-alpha3 - Authorization Bypass Through User-Controlled Key
CVE-2026-34044 HIGH
Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped)
CVSS 7.7
CVE-2026-34037 CRITICAL
Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()
CVSS 9.9
CVE-2026-53644 HIGH
FOSSBilling 0.5.3-0.7.2 Serviceapikey - API Key Secret Exposure
CVE-2026-53643 HIGH
FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
CVE-2026-34167 MEDIUM
Coolify: Cross-tenant activity log disclosure via unlocked Livewire property in ActivityMonitor
CVSS 5.0
CVE-2026-59712 HIGH
Leantime - Credential Disclosure via Unauthenticated JSON-RPC users.getUser Method
CVSS 8.1
CVE-2026-12686 CRITICAL
Incorrect authorisation in Adiss’s Biloop
CVE-2026-49099 MEDIUM
Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
CVSS 5.3
CVE-2026-48206 MEDIUM
Apache Camel Jira 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-46585 HIGH
Apache Camel Lucene 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 7.5
CVE-2026-46453 MEDIUM
Apache Camel 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-14793 MEDIUM
Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
CVSS 4.3
CVE-2026-14753 HIGH
mjperpinosa stumasy Note Handler/Assignment notes authorization
CVSS 7.3
Details
Vulnerabilities 2,101
Exploit Likelihood High