← Back
CWE-639

2,049 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (2,049)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Verint
1Workforce Optimization
Jul 9, 2026
Sep 22, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
11crm
11crm
Jun 17, 2026
Sep 18, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a...Show more
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 31, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
1Dbhcms Project
1Dbhcms
Jun 17, 2026
Aug 24, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
1Redhat
1Cloudforms
Jun 17, 2026
Aug 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible...Show more
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.Show less
1Apache
1Ofbiz
Jun 17, 2026
Jul 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
1Atlassian
4Jira
Jira Data CenterJira Server+1 more
Jun 17, 2026
Jul 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper....Show more
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version 8.10.0 before 8.10.1.Show less
1Linkplay
1Linkplay
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Lin...Show more
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.Show less
1Acf To Rest Api Project
1Acf To Rest Api
Jun 17, 2026
Jun 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that read...Show more
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.Show less
1Citrix
1Xenapp
Jun 17, 2026
Jun 11, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vuln...Show more
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
May 12, 2020
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
1Tecnick
1Tcexam
Jun 17, 2026
May 7, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.
1Oklok Project
1Oklok
Jun 17, 2026
May 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker...Show more
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker can use their own token to make unauthorized API requests on behalf of arbitrary user IDs. Valid and current user IDs are trivial to guess because of the user ID assignment convention used by the app. A remote attacker could harvest email addresses, unsalted MD5 password hashes, owner-assigned lock names, and owner-assigned fingerprint names for any range of arbitrary user IDs.Show less
1Pagerduty
1Rundeck
Jun 17, 2026
Apr 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck i...Show more
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. If access is tightly restricted and all users on the system have access to all projects, this is not really much of an issue. If access is wider and allows login for users that do not have access to any projects, or project access is restricted, there is a larger issue. If access is meant to be restricted and secrets, sensitive data, or intellectual property are exposed in Rundeck execution output and job data, the risk becomes much higher. This vulnerability is patched in version 3.2.6Show less
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
1Subex
1Roc Partner Settlement
Jun 17, 2026
Apr 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST paramete...Show more
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST parameters. NOTE: This vulnerability may only affect a testing version of the applicationShow less
1Cipplanner
1Cipace
Jun 17, 2026
Apr 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to au...Show more
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.Show less
1Dnnsoftware
1Dotnetnuke
Jun 17, 2026
Apr 6, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manag...Show more
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.Show less
1Totemo
1Totemomail
Jun 17, 2026
Mar 27, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.