CWE-639 - Authorization Bypass Through User-Controlled Key (IDOR) - Cwe

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
May 29, 2026
Last Seen
June 13, 2026

CWE-639 - Authorization Bypass Through User-Controlled Key (IDOR) is a cwe tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed May 29, 2026; most recent activity June 13, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-44207 CVE Vulnerability Disclosures / 1d Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0. — cve.report · June 13, 2026
  • CVE-2026-7787 - Unauthenticated Session History Access via Public Flow Execution — Cvefeed · June 11, 2026
  • CVE-2026-7201 TheHackerWire / 6h Attack Vector How the vulnerability can be exploited Network Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users. — www.thehackerwire.com · June 3, 2026
  • 5 Vulnerabilities in Every Vibe-Coded App — Strobes.Co · May 29, 2026

CVSS v3.1 Breakdown