← Back
CWE-639

2,049 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (2,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Partner Engagement Manager
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 21...Show more
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.Show less
1Rsa
1Archer
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
1Wowonder
1Wowonder
Jun 17, 2026
Mar 27, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Mar 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-2944...Show more
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.Show less
1Ayecode
1Userswp
Jun 17, 2026
Mar 7, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avat...Show more
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.Show less
1Open Emr
1Openemr
Jun 17, 2026
Mar 3, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/reg...Show more
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.Show less
1Pagerduty
1Rundeck
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a r...Show more
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed webhook tokens to trigger webhooks. Severity depends on trust level of authenticated users and whether any webhooks exist that trigger sensitive actions. There are patches for this vulnerability in versions 3.4.5 and 3.3.15. There are currently no known workarounds.Show less
11byte
9Copy9
ExactspyFonetracker+6 more
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Feb 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 20, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
1Mittwald
1Varnishcache
Jun 17, 2026
Feb 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to rende...Show more
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.Show less
1Ibexa
1Ez Platform Kernel
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 17, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
2Fedoraproject
Uri.js Project
2Fedora
Uri.js
Jun 17, 2026
Feb 16, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
1Scratchoauth2 Project
1Scratchoauth2
Jun 17, 2026
Feb 15, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is v...Show more
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.Show less
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
1Chatwoot
1Chatwoot
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
3Fedoraproject
GrafanaNetapp
3E Series Performance Analyzer
FedoraGrafana
Jun 17, 2026
Feb 8, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticate...Show more
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.Show less
1Ip2location
1Country Blocker
Jun 17, 2026
Feb 7, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL