← Back
CWE-639

2,514 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

JSON object

Loading...

CVEs (2,514)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Glpi Project
1Glpi
Jun 17, 2026
Nov 26, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
1Cisco
2Roomos
Telepresence Collaboration Endpoint
Jun 17, 2026
Nov 18, 2020
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due t...Show more
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific token. A successful exploit could allow the attacker to use the generated token to enable experimental features on the device that should not be available to users.Show less
1Citadel
1Webcit
Jun 17, 2026
Oct 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor...Show more
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.Show less
1Nextcloud
1Deck
Jun 17, 2026
Oct 5, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
1Ge
1Asset Performance Management Classic
Jun 17, 2026
Sep 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have...Show more
GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have access to such functionality. An attacker can download sensitive data related to user accounts without having the proper privileges.Show less
1Verint
1Workforce Optimization
Jul 9, 2026
Sep 22, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
11crm
11crm
Jun 17, 2026
Sep 18, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a...Show more
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Aug 31, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
1Dbhcms Project
1Dbhcms
Jun 17, 2026
Aug 24, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
1Redhat
1Cloudforms
Jun 17, 2026
Aug 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible...Show more
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.Show less
1Apache
1Ofbiz
Jun 17, 2026
Jul 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
1Atlassian
4Jira
Jira Data CenterJira Server+1 more
Jun 17, 2026
Jul 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper....Show more
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version 8.10.0 before 8.10.1.Show less
1Linkplay
1Linkplay
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Lin...Show more
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.Show less
1Acf To Rest Api Project
1Acf To Rest Api
Jun 17, 2026
Jun 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that read...Show more
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.Show less
1Citrix
1Xenapp
Jun 17, 2026
Jun 11, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vuln...Show more
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
May 12, 2020
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
1Tecnick
1Tcexam
Jun 17, 2026
May 7, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.
1Oklok Project
1Oklok
Jun 17, 2026
May 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker...Show more
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker can use their own token to make unauthorized API requests on behalf of arbitrary user IDs. Valid and current user IDs are trivial to guess because of the user ID assignment convention used by the app. A remote attacker could harvest email addresses, unsalted MD5 password hashes, owner-assigned lock names, and owner-assigned fingerprint names for any range of arbitrary user IDs.Show less
1Pagerduty
1Rundeck
Jun 17, 2026
Apr 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck i...Show more
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. If access is tightly restricted and all users on the system have access to all projects, this is not really much of an issue. If access is wider and allows login for users that do not have access to any projects, or project access is restricted, there is a larger issue. If access is meant to be restricted and secrets, sensitive data, or intellectual property are exposed in Rundeck execution output and job data, the risk becomes much higher. This vulnerability is patched in version 3.2.6Show less
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.