Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne
Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of
Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med
Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and
Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta
Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserContr
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monito
Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.
Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privil
Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,
Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspa
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers t
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScript
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchore
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method th
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticate
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list r
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6,
Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. Authorizat
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to t
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restauran
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t
Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploit
FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 1,321 CVE records associated with CWE-639 in our database. Of these, 86 are critical severity, 358 are high severity, and 663 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started