CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
2,105 vulnerabilities with CWE-639
CVE-2026-48206
MEDIUM
Apache Camel Jira 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-46585
HIGH
Apache Camel Lucene 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 7.5
CVE-2026-46453
MEDIUM
Apache Camel 4.14.8, 4.18.3, and 4.21.0 - Authorization Bypass
CVSS 5.3
CVE-2026-14793
MEDIUM
Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
CVSS 4.3
CVE-2026-14753
HIGH
mjperpinosa stumasy Note Handler/Assignment notes authorization
CVSS 7.3
CVE-2026-28740
HIGH
Gitea LFS object reuse bypasses Code-unit authorization
CVSS 7.1
CVE-2026-27657
HIGH
Gitea email settings allow changing another user's primary email address
CVSS 7.5
CVE-2026-25782
MEDIUM
Gitea tracked-time deletion can target entries from another issue
CVSS 5.3
CVE-2026-14608
MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorization
CVSS 4.3
CVE-2026-14614
MEDIUM
Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource
CVSS 5.4
CVE-2026-59234
MEDIUM
Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion
CVE-2026-11900
MEDIUM
Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
CVSS 4.3
CVE-2026-9180
MEDIUM
MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter
CVSS 5.3
CVE-2026-59100
MEDIUM
LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
CVSS 5.0
CVE-2026-59098
MEDIUM
LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
CVSS 6.5
CVE-2026-58580
MEDIUM
LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Writes
CVSS 5.9
CVE-2026-58653
MEDIUM
PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update
CVSS 4.3
CVE-2026-57680
MEDIUM
WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2026-9188
MEDIUM
Wappointment <= 2.7.6 - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-12657
MEDIUM
LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
CVSS 5.3
CVE-2026-11896
MEDIUM
My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter
CVSS 5.3
CVE-2026-5348
MEDIUM
Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure
CVSS 5.3
CVE-2026-50283
MEDIUM
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-49858
MEDIUM
API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
CVSS 5.9
CVE-2026-5142
MEDIUM
Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass
CVSS 6.5
Details
Vulnerabilities
2,105
Exploit Likelihood
High