Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-639'

View all threats tagged with 'cwe-639'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-639

Threats Tagged 'cwe-639'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-48765: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.ioCVE-2026-48765
0

TypeBot versions prior to 3.17.0 contain an authorization bypass vulnerability allowing a low-privilege read collaborator to extract and overwrite OAuth credentials across workspaces. This flaw enables cross-workspace OAuth credential takeover by exploiting insufficient validation in the credential update process. The issue is patched in version 3.17.0.

Join the discussion
CVE-2026-19579: CWE-639 Authorization bypass through User-Controlled key in Grokability Snipe-ITCVE-2026-19579
0

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.

Join the discussion
CVE-2026-48494: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.ioCVE-2026-48494
0

TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number tied to another preview session. The WhatsApp test-webhook handler authorizes the parent typebot first, but then resolves the preview chat session only by `wa-preview-{phone}`. As a result, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft/unpublished flow without any access to the victim typebot. Version 3.17.0 patches the issue.

Join the discussion
CVE-2026-58650: CWE-639: Authorization Bypass Through User-Controlled Key in Microsoft Visual Studio CodeCVE-2026-58650
0

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Join the discussion
CVE-2026-47704: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.ioCVE-2026-47704
0

TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign live `resultId`. The webhook resume handler authorizes the parent typebot first, but then resolves the descendant `result` only by `resultId`. As a result, an attacker can inject arbitrary webhook JSON into another typebot's suspended session and advance its execution without any access to the victim typebot. Version 3.17.0 patches the issue.

Join the discussion
CVE-2026-72545: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs OpenSignCVE-2026-72545
0

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials.

Join the discussion
CVE-2026-72543: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs OpenSignCVE-2026-72543
0

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials.

Join the discussion
CVE-2026-19424: CWE-639 Authorization Bypass Through User-Controlled Key in Inventec Appliances Chiline CloudCVE-2026-19424
0

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.

Join the discussion
CVE-2026-66764: CWE-639: Authorization Bypass Through User-Controlled Key in SAP_SE SAP S/4 HANA (Reprocess Bank Statement Items)CVE-2026-66764
0

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application

Join the discussion
CVE-2026-18620: Authorization Bypass Through User-Controlled Key in Red Hat Red Hat OpenShift AI 2.25CVE-2026-18620
0

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods.

Join the discussion

Showing 1 to 10 of 170 results

Filters:Tag: cwe-639
Page 1 of 17
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses