CWE-639
2,049 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVEs (2,049)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Partner Engagement Manager Jun 17, 2026 Apr 1, 2022 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 21...Show more |
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data. |
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names. |
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-2944...Show more |
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avat...Show more |
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/reg...Show more |
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a r...Show more |
11byte 9Copy9 ExactspyFonetracker+6 moreJun 17, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability. |
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0. |
1Url Parse Project 1Url Parse Jun 17, 2026 Feb 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. |
1Url Parse Project 1Url Parse Jun 17, 2026 Feb 20, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. |
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to rende...Show more |
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced. |
1Url Parse Project 1Url Parse Jun 17, 2026 Feb 17, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. |
2Fedoraproject Uri.js Project2Fedora Uri.jsJun 17, 2026 Feb 16, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. |
1Scratchoauth2 Project 1Scratchoauth2 Jun 17, 2026 Feb 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is v...Show more |
1Url Parse Project 1Url Parse Jun 17, 2026 Feb 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. |
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. |
3Fedoraproject GrafanaNetapp3E Series Performance Analyzer FedoraGrafanaJun 17, 2026 Feb 8, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticate...Show more |
1Ip2location 1Country Blocker Jun 17, 2026 Feb 7, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL |