NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenti
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization b
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a
An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Acc
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers t
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific con
The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors a
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studioc
SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin
Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12,
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against El
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret o
Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5,
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploit
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to cha
StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a
A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Deni
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_
Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subsc
An improper access control vulnerability exists where an authenticated user could access areas outside of their authoriz
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows f
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started