CWE-639 · 2,471 records
Authorization bypass through user-controlled key
Why does it happen?
The endpoint fetches the record by the ID sent in the request, but never checks whether the record belongs to the requesting user.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
const invoice = await Invoice.findById(req.params.id);res.json(invoice);Fixed
const invoice = await Invoice.findOne({ id: req.params.id, ownerId: req.user.id,});if (!invoice) return res.sendStatus(404);res.json(invoice);How to prevent it
- 01Add the session user as a condition to every query.
- 02Centralize ownership checks in a single authorization layer.
- 03Write cross-access tests using two different accounts.
CVEs in this class
2,474 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2023-6875Weaponized | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app APIwpexperts · post smtp · CWE-639 | Critical9.8 | — | 90.3% | Jan 11, 2024 |
63This week | CVE-2026-55255Weaponized | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flowlangflow · langflow · CWE-639 | High8.4 | KEV | 0.9% | Jun 23, 2026 |
56Plan | CVE-2021-45428Proof of concept | TLR-2005KSH is affected by an incorrect access control vulnerability.telesquare · tlr-2005ksh firmware · CWE-639 | Critical9.8 | — | 56.9% | Jan 3, 2022 |
52Plan | CVE-2019-17382Proof of concept | An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4.zabbix · zabbix · CWE-639 | Critical9.1 | — | 54.2% | Oct 9, 2019 |
48Plan | CVE-2024-46982Proof of concept | Cache Poisoning in next.jsvercel · next.js · CWE-639 | High7.5 | — | 59.2% | Sep 17, 2024 |
47Plan | CVE-2025-2563Weaponized | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalationwpeverest · user registration \& membership · CWE-639 | High8.1 | — | 48.8% | Apr 14, 2025 |
46Plan | CVE-2019-13360Proof of concept | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging kcontrol-webpanel · webpanel · CWE-639 | Critical9.8 | — | 24.5% | Jul 16, 2019 |
44Plan | CVE-2024-0264No exploit | SourceCodester Clinic Queuing System LoginRegistration.php authorizationoretnom23 · clinic queuing system · CWE-639 | Critical9.8 | — | 18.2% | Jan 7, 2024 |
43Plan | CVE-2022-22832Proof of concept | An issue was discovered in Servisnet Tessa 0.0.2.servisnet · tessa · CWE-639 | Critical9.8 | — | 14.1% | Feb 6, 2022 |
41Plan | CVE-2025-3605Proof of concept | Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeoverarkenon · login, registration and lost password blocks · CWE-639 | Critical9.8 | — | 6.9% | May 9, 2025 |
40Plan | CVE-2019-13605Proof of concept | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process bycontrol-webpanel · webpanel · CWE-639 | High8.8 | — | 15.3% | Jul 16, 2019 |
40Plan | CVE-2019-6716Proof of concept | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a rlogonbox · nervepoint access manager · CWE-639 | Critical9.4 | — | 9.6% | Mar 21, 2019 |
40Plan | CVE-2025-5947Proof of concept | Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookieaonetheme · service finder bookings · CWE-639 | Critical9.8 | — | 4.4% | Aug 1, 2025 |
40Plan | CVE-2022-31692Proof of concept | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or includvmware · spring security · CWE-639 | Critical9.8 | — | 3.6% | Oct 31, 2022 |
40Plan | CVE-2020-11658No exploit | CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.broadcom · ca api developer portal · CWE-639 | Critical9.8 | — | 2.4% | Apr 15, 2020 |
40Plan | CVE-2024-50483Proof of concept | WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerabilitytareqhasan · meetup · CWE-639 | Critical9.8 | — | 2.3% | Oct 28, 2024 |
40Plan | CVE-2022-0691No exploit | Authorization Bypass Through User-Controlled Key in unshiftio/url-parseurl-parse project · url-parse · CWE-639 | Critical9.8 | — | 2.2% | Feb 21, 2022 |
40Plan | CVE-2019-9756No exploit | An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, gitlab · gitlab · CWE-639 | Critical9.8 | — | 2.2% | Apr 17, 2019 |
40Plan | CVE-2019-12866No exploit | An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack.jetbrains · youtrack · CWE-639 | Critical9.8 | — | 1.9% | Jul 3, 2019 |
40Plan | CVE-2025-14998Proof of concept | Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeoverwpmudev · branda – white label & branding, free login page customizer · CWE-639 | Critical9.8 | — | 1.9% | Jan 1, 2026 |
40Plan | CVE-2026-83711No exploit | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerabilitymicrosoft · entra · CWE-639 | Critical10.0 | — | 0.8% | Sep 3, 2026 |
40Plan | CVE-2026-69865No exploit | Microsoft Container Registry Elevation of Privilege Vulnerabilitymicrosoft · azure container registry · CWE-639 | Critical10.0 | — | 0.8% | Sep 17, 2026 |
40Plan | CVE-2024-45032No exploit | A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versisiemens · industrial edge management pro · CWE-639 | Critical10.0 | — | 0.8% | Sep 10, 2024 |
40Plan | CVE-2025-40805No exploit | Affected devices do not properly enforce user authentication on specific API endpoints.siemens · industrial edge cloud device (iecd) · CWE-639 | Critical10.0 | — | 0.7% | Jan 13, 2026 |
40Plan | CVE-2026-77998No exploit | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Lminiorange.com · saml sso free for joomla extension for joomla · CWE-639 | Critical10.0 | — | 0.6% | Aug 25, 2026 |
- CVE-2023-687566This week
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
CriticalCVSS 9.8WeaponizedEPSS 90%wpexperts · post smtpJan 11, 2024
- CVE-2026-5525563This week
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
HighCVSS 8.4KEVWeaponizedEPSS 1%langflow · langflowJun 23, 2026
- CVE-2021-4542856Plan
TLR-2005KSH is affected by an incorrect access control vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 57%telesquare · tlr-2005ksh firmwareJan 3, 2022
- CVE-2019-1738252Plan
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4.
CriticalCVSS 9.1Proof of conceptEPSS 54%zabbix · zabbixOct 9, 2019
- CVE-2024-4698248Plan
Cache Poisoning in next.js
HighCVSS 7.5Proof of conceptEPSS 59%vercel · next.jsSep 17, 2024
- CVE-2025-256347Plan
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
HighCVSS 8.1WeaponizedEPSS 49%wpeverest · user registration \& membershipApr 14, 2025
- CVE-2019-1336046Plan
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging k
CriticalCVSS 9.8Proof of conceptEPSS 24%control-webpanel · webpanelJul 16, 2019
- CVE-2024-026444Plan
SourceCodester Clinic Queuing System LoginRegistration.php authorization
CriticalCVSS 9.8No exploitEPSS 18%oretnom23 · clinic queuing systemJan 7, 2024
- CVE-2022-2283243Plan
An issue was discovered in Servisnet Tessa 0.0.2.
CriticalCVSS 9.8Proof of conceptEPSS 14%servisnet · tessaFeb 6, 2022
- CVE-2025-360541Plan
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
CriticalCVSS 9.8Proof of conceptEPSS 7%arkenon · login, registration and lost password blocksMay 9, 2025
- CVE-2019-1360540Plan
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by
HighCVSS 8.8Proof of conceptEPSS 15%control-webpanel · webpanelJul 16, 2019
- CVE-2019-671640Plan
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a r
CriticalCVSS 9.4Proof of conceptEPSS 10%logonbox · nervepoint access managerMar 21, 2019
- CVE-2025-594740Plan
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
CriticalCVSS 9.8Proof of conceptEPSS 4%aonetheme · service finder bookingsAug 1, 2025
- CVE-2022-3169240Plan
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or includ
CriticalCVSS 9.8Proof of conceptEPSS 4%vmware · spring securityOct 31, 2022
- CVE-2020-1165840Plan
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
CriticalCVSS 9.8No exploitEPSS 2%broadcom · ca api developer portalApr 15, 2020
- CVE-2024-5048340Plan
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%tareqhasan · meetupOct 28, 2024
- CVE-2022-069140Plan
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
CriticalCVSS 9.8No exploitEPSS 2%url-parse project · url-parseFeb 21, 2022
- CVE-2019-975640Plan
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6,
CriticalCVSS 9.8No exploitEPSS 2%gitlab · gitlabApr 17, 2019
- CVE-2019-1286640Plan
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack.
CriticalCVSS 9.8No exploitEPSS 2%jetbrains · youtrackJul 3, 2019
- CVE-2025-1499840Plan
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover
CriticalCVSS 9.8Proof of conceptEPSS 2%wpmudev · branda – white label & branding, free login page customizerJan 1, 2026
- CVE-2026-8371140Plan
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CriticalCVSS 10.0No exploitEPSS 1%microsoft · entraSep 3, 2026
- CVE-2026-6986540Plan
Microsoft Container Registry Elevation of Privilege Vulnerability
CriticalCVSS 10.0No exploitEPSS 1%microsoft · azure container registrySep 17, 2026
- CVE-2024-4503240Plan
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versi
CriticalCVSS 10.0No exploitEPSS 1%siemens · industrial edge management proSep 10, 2024
- CVE-2025-4080540Plan
Affected devices do not properly enforce user authentication on specific API endpoints.
CriticalCVSS 10.0No exploitEPSS 1%siemens · industrial edge cloud device (iecd)Jan 13, 2026
- CVE-2026-7799840Plan
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – L
CriticalCVSS 10.0No exploitEPSS 1%miniorange.com · saml sso free for joomla extension for joomlaAug 25, 2026