← Back
CWE-639

2,049 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (2,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Servisnet
1Tessa
Jun 17, 2026
Feb 6, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
1Classapps
1Selectsurvey.net
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of th...Show more
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in sequential order beginning from 1.Show less
1Synametrics
1Synaman
Jun 17, 2026
Jan 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
1Saviynt
1Enterprise Identity Cloud
Jun 17, 2026
Jan 24, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Jan 19, 2022
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
1Deltarm
1Delta Rm
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID paramet...Show more
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.Show less
1Hp
27Designjet T1530 L2y23a Firmware
Designjet T1530 L2y24a FirmwareDesignjet T1530 L2y24b Firmware+24 more
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.
1Weseek
1Growi
Jun 17, 2026
Jan 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
growi is vulnerable to Authorization Bypass Through User-Controlled Key
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Jan 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
1Cth
1Carinal Tien Hospital Health Report System
Jun 17, 2026
Dec 29, 2021
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker c...Show more
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.Show less
1Online Enrollment Management System Project
1Online Enrollment Management System
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. The impact is: gain privileges (remote).
1Shapedplugin
1Logo Carousel
Jun 17, 2026
Dec 21, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
1Patrowl
1Patrowlmanager
Jun 17, 2026
Dec 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed un...Show more
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id is predictable and tmp_file is in format of import_<ownder_id>_<time_created>, for example: import_1_1639213059582.json This filename is predictable and allows anyone without logging in to download all finding import files This vulnerability is capable of allowing unlogged in users to download all finding imports file. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds.Show less
1Seafile
1Seafile Server
Jun 17, 2026
Dec 14, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiv...Show more
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server checks whether the token exist in the cache. However, if the token exists in cache, the server doesn't check whether it's associated with the specific library in the URL. This vulnerability makes it possible to use any valid sync token to access data from any **known** library. Note that the attacker has to first find out the ID of a library which it has no access to. The library ID is a random UUID, which is not possible to be guessed. There are no workarounds for this issue.Show less
1Glfusion
1Glfusion
Jun 17, 2026
Dec 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting fro...Show more
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions s...Show more
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.Show less
1Elgg
1Elgg
Jun 17, 2026
Dec 1, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
1Kimai2 Project
1Kimai2
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
kimai2 is vulnerable to Improper Access Control
1Dell
1Emc Streaming Data Platform
Jun 17, 2026
Nov 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.