CWE-639
CVEs classified under CWE-639, newest first.
670 CVEsRSS
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-53863MediumOpenClaw: Tool group policy callers could accept unvalidated group IDs
OpenClaw: Tool group policy callers could accept unvalidated group IDs
CVE-2026-55670LowZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
GHSA-2fjj-qqg8-fg7xMedium· 4.3praisonai-platform: Authorization Bypass Through User-Controlled Key
praisonai-platform: Authorization Bypass Through User-Controlled Key
CVE-2026-54683Medium· 6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
GHSA-hjwc-26pj-v3pmHighAgenticMail: Cross-agent task authorization bypass in AgenticMail API
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
CVE-2026-55198Medium· 6.5PoCHermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles
Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails …
CVE-2026-55197Medium· 6.5PoCHermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts
Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by direc…
CVE-2026-54006Medium· 4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
CVE-2026-54009Medium· 6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2026-54010High· 8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54015Medium· 6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVE-2026-55518Critical· 9.6Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
CVE-2026-33760High· 8.8Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
GHSA-8wmm-344f-mpjgMedium· 7.1Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
CVE-2026-48599High· 7.6PoCAuthorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…
CVE-2026-54097HighFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-48067Medium· 6.5Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
CVE-2026-47068LowPhoenixStorybook has cross-session PubSub topic injection via URL parameter
PhoenixStorybook has cross-session PubSub topic injection via URL parameter
CVE-2026-45810Medium· 6.8Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file commen…
CVE-2026-42999High· 8.3⚖ disputedopenstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection (CVE-2026-429…
A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perfo…
CVE-2026-35430High· 8.8Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
CVE-2026-7886Medium· 4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file …
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file …
CVE-2026-47101High· 8.8PoCLiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…
CVE-2026-9087Medium· 6.4A flaw was found in Keycloak
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume i…
CVE-2026-44283Medium· 4.3⚖ disputedetcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)
A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…
CVE-2026-41950Medium· 6.5Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files …
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files …
CVE-2026-28747High· 7.1A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.