CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

2,105 vulnerabilities with CWE-639
CVE-2026-48206 MEDIUM
Apache Camel Jira 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-46585 HIGH
Apache Camel Lucene 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 7.5
CVE-2026-46453 MEDIUM
Apache Camel 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-14793 MEDIUM
Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
CVSS 4.3
CVE-2026-14753 HIGH
mjperpinosa stumasy Note Handler/Assignment notes authorization
CVSS 7.3
CVE-2026-28740 HIGH
Gitea LFS object reuse bypasses Code-unit authorization
CVSS 7.1
CVE-2026-27657 HIGH
Gitea email settings allow changing another user's primary email address
CVSS 7.5
CVE-2026-25782 MEDIUM
Gitea tracked-time deletion can target entries from another issue
CVSS 5.3
CVE-2026-14608 MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorization
CVSS 4.3
CVE-2026-14614 MEDIUM
Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource
CVSS 5.4
CVE-2026-59234 MEDIUM
Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion
CVE-2026-11900 MEDIUM
Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
CVSS 4.3
CVE-2026-9180 MEDIUM
MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter
CVSS 5.3
CVE-2026-59100 MEDIUM
LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
CVSS 5.0
CVE-2026-59098 MEDIUM
LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
CVSS 6.5
CVE-2026-58580 MEDIUM
LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Writes
CVSS 5.9
CVE-2026-58653 MEDIUM
PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update
CVSS 4.3
CVE-2026-57680 MEDIUM
WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-9188 MEDIUM
Wappointment <= 2.7.6 - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-12657 MEDIUM
LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
CVSS 5.3
CVE-2026-11896 MEDIUM
My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter
CVSS 5.3
CVE-2026-5348 MEDIUM
Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure
CVSS 5.3
CVE-2026-50283 MEDIUM
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-49858 MEDIUM
API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
CVSS 5.9
CVE-2026-5142 MEDIUM
Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass
CVSS 6.5
Details
Vulnerabilities 2,105
Exploit Likelihood High