← Back
CWE-639

2,515 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (2,515)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tylertech
1Odyssey Portal
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.
1Kentico
1Xperience
Jun 17, 2026
Apr 16, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher...Show more
Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).Show less
1Juniper
1Paragon Active Assurance Control Center
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensit...Show more
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature was introduced in version 3.1 of the Paragon Active Assurance Control Center which allows users to selective share account data using a unique identifier. Knowing the proper format of the URL and the identifier of an existing object in an application it is possible to get access to that object without being logged in, even if the object is not shared, resulting in the opportunity for malicious exfiltration of user data. Note that the Paragon Active Assurance Control Center SaaS offering is not affected by this issue. This issue affects Juniper Networks Paragon Active Assurance version 3.1.0.Show less
1Sma
1Sunny Tripower Firmware
Jul 13, 2026
Apr 7, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
1Orangehrm
1Orangehrm
Jun 17, 2026
Apr 6, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
1Plugin Planet
1Blackhole For Bad Bots
Jun 17, 2026
Apr 4, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could...Show more
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.Show less
1Ibm
1Partner Engagement Manager
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 21...Show more
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.Show less
1Rsa
1Archer
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
1Wowonder
1Wowonder
Jun 17, 2026
Mar 27, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Mar 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-2944...Show more
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.Show less
1Ayecode
1Userswp
Jun 17, 2026
Mar 7, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avat...Show more
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.Show less
1Open Emr
1Openemr
Jun 17, 2026
Mar 3, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/reg...Show more
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.Show less
1Pagerduty
1Rundeck
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a r...Show more
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed webhook tokens to trigger webhooks. Severity depends on trust level of authenticated users and whether any webhooks exist that trigger sensitive actions. There are patches for this vulnerability in versions 3.4.5 and 3.3.15. There are currently no known workarounds.Show less
11byte
9Copy9
ExactspyFonetracker+6 more
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Feb 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 20, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
1Mittwald
1Varnishcache
Jun 17, 2026
Feb 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to rende...Show more
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.Show less
1Ibexa
1Ez Platform Kernel
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
1Url Parse Project
1Url Parse
Jun 17, 2026
Feb 17, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.