Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS
Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain
Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calend
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised acce
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st
FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticate
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t
R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl
grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5
ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the
OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3
A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule
Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListContro
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, Pro
n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in wo
stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Pro
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp
Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-p
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platfor
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows una
The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` me
The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of
Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organiz
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authent
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenti
TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can
TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resum
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-dr
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows
@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-r
Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpo
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started