CWE-639
2,514 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVEs (2,514)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.). |
1Cisco 2Roomos Telepresence Collaboration EndpointJun 17, 2026 Nov 18, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due t...Show more |
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor...Show more |
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments. |
1Ge 1Asset Performance Management Classic Jun 17, 2026 Sep 23, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have...Show more |
1Verint 1Workforce Optimization Jul 9, 2026 Sep 22, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API |
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Aug 31, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address. |
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content. |
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible...Show more |
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreJun 17, 2026 Jul 13, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper....Show more |
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Lin...Show more |
1Acf To Rest Api Project 1Acf To Rest Api Jun 17, 2026 Jun 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that read...Show more |
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vuln...Show more |
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint. |
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission. |
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker...Show more |
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck i...Show more |
1Broadcom 1Ca Api Developer Portal Jun 17, 2026 Apr 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action. |