Threats Tagged 'cwe-639'
View all threats tagged with 'cwe-639'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-639'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-48765: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.ioCVE-2026-48765 0 TypeBot versions prior to 3.17.0 contain an authorization bypass vulnerability allowing a low-privilege read collaborator to extract and overwrite OAuth credentials across workspaces. This flaw enables cross-workspace OAuth credential takeover by exploiting insufficient validation in the credential update process. The issue is patched in version 3.17.0. Join the discussion | CVE Database V5 | 08/11/2026, 20:37:48 UTC Added: 08/11/2026, 20:56:49 UTC |
CVE-2026-19579: CWE-639 Authorization bypass through User-Controlled key in Grokability Snipe-ITCVE-2026-19579 0 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0. Join the discussion | CVE Database V5 | 08/11/2026, 20:25:02 UTC Added: 08/11/2026, 20:26:54 UTC |
CVE-2026-48494: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.ioCVE-2026-48494 0 TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number tied to another preview session. The WhatsApp test-webhook handler authorizes the parent typebot first, but then resolves the preview chat session only by `wa-preview-{phone}`. As a result, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft/unpublished flow without any access to the victim typebot. Version 3.17.0 patches the issue. Join the discussion | CVE Database V5 | 08/11/2026, 17:09:33 UTC Added: 08/11/2026, 17:42:02 UTC |
CVE-2026-58650: CWE-639: Authorization Bypass Through User-Controlled Key in Microsoft Visual Studio CodeCVE-2026-58650 0 Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Join the discussion | CVE Database V5 | 08/11/2026, 17:03:24 UTC Added: 08/11/2026, 17:12:26 UTC |
CVE-2026-47704: CWE-639: Authorization Bypass Through User-Controlled Key in baptisteArno typebot.ioCVE-2026-47704 0 TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign live `resultId`. The webhook resume handler authorizes the parent typebot first, but then resolves the descendant `result` only by `resultId`. As a result, an attacker can inject arbitrary webhook JSON into another typebot's suspended session and advance its execution without any access to the victim typebot. Version 3.17.0 patches the issue. Join the discussion | CVE Database V5 | 08/11/2026, 16:23:07 UTC Added: 08/11/2026, 16:26:50 UTC |
CVE-2026-72545: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs OpenSignCVE-2026-72545 0 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials. Join the discussion | CVE Database V5 | 08/11/2026, 11:09:17 UTC Added: 08/11/2026, 11:26:59 UTC |
CVE-2026-72543: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs OpenSignCVE-2026-72543 0 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials. Join the discussion | CVE Database V5 | 08/11/2026, 11:08:45 UTC Added: 08/11/2026, 11:26:59 UTC |
CVE-2026-19424: CWE-639 Authorization Bypass Through User-Controlled Key in Inventec Appliances Chiline CloudCVE-2026-19424 0 Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data. Join the discussion | CVE Database V5 | 08/11/2026, 01:56:10 UTC Added: 08/11/2026, 02:26:47 UTC |
CVE-2026-66764: CWE-639: Authorization Bypass Through User-Controlled Key in SAP_SE SAP S/4 HANA (Reprocess Bank Statement Items)CVE-2026-66764 0 Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application Join the discussion | CVE Database V5 | 08/11/2026, 00:18:00 UTC Added: 08/11/2026, 00:42:06 UTC |
CVE-2026-18620: Authorization Bypass Through User-Controlled Key in Red Hat Red Hat OpenShift AI 2.25CVE-2026-18620 0 A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods. Join the discussion | CVE Database V5 | 08/10/2026, 20:45:43 UTC Added: 08/10/2026, 20:56:54 UTC |
Showing 1 to 10 of 170 results