Skip to content
Threat Feed

Tag

Idor

53 briefs RSS
high advisory

Cross-Tenant IDOR in Convoy API Exposes Broker Credentials

Convoy versions up to and including 26.6.2 contain an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to leak plaintext message broker credentials from other tenants.

convoy idor credential-leak api-security
2t 1c
high advisory

IDOR Vulnerability in SIMAC MyPHR

SIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.

MyPHR idor web-vulnerability vulnerability cve-2026-47094
2t 1c
critical advisory

Multi-tenant Isolation Bypass in djust via WebSocket/SSE

A vulnerability in djust caused multi-tenant isolation to fail open on WebSocket and SSE paths, allowing unauthorized cross-tenant data disclosure due to improper tenant context propagation.

djust +1 web-application mass-assignment cve-2026-61598 remote-code-execution information-disclosure cve-2026-61590 idor broken-access-control +5
6t 1c updated
high advisory

IDOR Vulnerability in Bookly WordPress Plugin

An Insecure Direct Object Reference (IDOR) vulnerability in the Bookly WordPress plugin allows unauthenticated attackers to enumerate and exfiltrate private AI booking transcripts via sequential ID incrementation.

Bookly web-application wordpress idor cve-2026-89063
2t 1c
medium threat

Authenticated IDOR Vulnerability in FlowForms

An authenticated Insecure Direct Object Reference (IDOR) vulnerability in FlowForms version 1.1.1 and earlier allows attackers with contributor-level access to modify arbitrary forms.

exploited FlowForms idor web-vulnerability cve-2026-12400
1r 1t 1c
high advisory

Insecure Direct Object Reference in CAPEv2 REST API

CAPEv2 versions up to commit 471ee4b contain an IDOR vulnerability allowing authenticated users to access and delete arbitrary analysis tasks.

CAPEv2 webserver idor api-security
1t 1c
critical advisory

Path Traversal Vulnerability in IBM DataStage

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal during archive extraction, allowing an authenticated remote attacker to create arbitrary files on the host system.

DataStage +1 vulnerability path-traversal cloud-security idor
2t 1c
high advisory

Identrail Cross-tenant IDOR via GitHub App Installation ID

An improper validation vulnerability in Identrail allows authenticated tenants to perform cross-tenant access to private GitHub repository metadata by supplying an arbitrary installation_id during the connection flow.

Identrail idor github cloud saas
2t
critical advisory

CVE-2026-16310 Unauthenticated Password Reset in MemberDash

The MemberDash WordPress plugin contains an IDOR vulnerability allowing unauthenticated attackers to perform unauthorized password resets for arbitrary users via the registration registration process.

MemberDash web-application wordpress idor account-takeover
1r 2t 1c
medium advisory

Concrete CMS IDOR Vulnerability in Conversation Rating Endpoint

Concrete CMS versions prior to 9.5.1 contain an IDOR vulnerability in the get_rating endpoint that allows unauthenticated attackers to enumerate message IDs and disclose rating data for private content.

Concrete Cms idor information-disclosure web-application reconnaissance
1r 1t 1c
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
high advisory

IDOR Vulnerability in Weblate GroupViewSet API

An Insecure Direct Object Reference vulnerability (CVE-2026-55228) in the Weblate GroupViewSet API allows authenticated project managers to gain unauthorized read access to private projects via manipulated team configurations.

Weblate idor api-vulnerability access-control
1t 1c
high advisory

CVE-2024-11318 Session Hijacking in AbsysNet

An Insecure Direct Object Reference (IDOR) vulnerability in AbsysNet 2.3.1 allows remote, unauthenticated attackers to hijack active user sessions via brute-force enumeration of session identifiers.

AbsysNet web-application idor session-hijacking
1r 2t 1c
high advisory

IDOR Vulnerability in Label Studio Annotation API

Label Studio contains an insecure direct object reference (IDOR) vulnerability, CVE-2026-76073, allowing authenticated users to read, modify, or delete annotations across organizational boundaries by enumerating sequential identifiers.

Label Studio idor api-security data-exfiltration
2t 1c
high advisory

Broken Access Control in Rainbond API

Rainbond through version 6.9.7 contains an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-72741) in the CheckToken function, allowing authenticated attackers to access or modify resources of other enterprise tenants.

Rainbond idor cloud-native broken-access-control
1r 1t 1c
high advisory

Insecure Direct Object Reference in better-auth passkey

An Insecure Direct Object Reference (IDOR) vulnerability (CVE-2025-71400) in better-auth passkey versions before 1.4.0 allows authenticated users to delete arbitrary passkeys by enumerating IDs.

passkey idor authentication web-application cve-2025-71400
1r 1t 1c
medium advisory

Poweradmin: Broken Access Control (IDOR) Allows DNS Record Modification

A low-privilege authenticated user in Poweradmin (a web front-end for PowerDNS) can exploit an Insecure Direct Object Reference (IDOR) vulnerability, allowing them to modify any DNS record on the server, even those they do not own, by manipulating POST request parameters to bypass access control checks and achieve DNS record repointing, disabling, or hijacking, leading to data integrity and availability issues, and potentially cross-tenant DNS takeover.

Poweradmin +2 idor dns-takeover web-application vulnerability access-control
3t 5i
high advisory

sysPass Insecure Direct Object Reference Vulnerability (CVE-2026-65708)

An insecure direct object reference vulnerability (CVE-2026-65708) in sysPass versions up to 3.2.11 allows authenticated attackers to bypass access controls, accessing, enumerating, and manipulating account file attachments by manipulating numeric file IDs in `AccountFileController` actions without proper authorization checks, leading to unauthorized data access.

sysPass <= 3.2.11 idor access-control-bypass web-application data-exfiltration
2t 1c
critical advisory

CyberPanel Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-65917)

An Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-65917, exists in CyberPanel versions through 1.9.1, specifically within the IncBackups application's incremental-backup handlers, allowing authenticated panel users to exploit attacker-controlled IncJob integer IDs to access, read metadata from, delete, or trigger unauthorized restoration of other tenants' backup resources, potentially leading to operations with root privileges.

CyberPanel vulnerability idor web-panel privilege-escalation data-manipulation
3t 1c
critical advisory

Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)

A critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.

Serv-U +1 remote-code-execution privilege-escalation vulnerability-exploitation vulnerability cve improper-access-control server software-update +5
5t 8c 3i
critical advisory

SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability Allows Privilege Escalation and RCE

A critical insecure direct object reference (IDOR) vulnerability, CVE-2026-28302, in SolarWinds Serv-U allows authenticated group administrators to achieve privilege escalation and remote code execution as root.

Serv-U +2 idor privilege-escalation rce file-transfer vulnerability solarwinds
3t 4c
high advisory

ArcadeDB Cross-Database IDOR Vulnerability Allows Unauthorized Data Access

ArcadeDB server versions prior to 26.7.2 are vulnerable to a cross-database Insecure Direct Object Reference (IDOR) due to improper authorization checks in several HTTP handlers, enabling a user authorized for a specific database to gain full read and write access to other unauthorized databases by directly accessing specific API endpoints.

arcadedb-server idor authorization-bypass arcadedb web-application
1r 1t
high advisory

Krayin CRM Insecure Direct Object Reference Vulnerability (CVE-2026-61460)

An Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-61460, in Krayin CRM through version 2.2.3 allows authenticated users to modify, update, or delete records owned by other users by exploiting missing record-level ownership validation in various controllers, leading to unauthorized data manipulation.

Krayin CRM +1 idor crm web-application vulnerability
3t 1c
critical advisory

Authorization Flaws in Vikunja Expose Share Hashes and Allow Attachment Manipulation

Authorization flaws in Vikunja before version 2.2.1 allow authenticated users with read access to escalate privileges by obtaining admin-level share hashes via the LinkSharing.ReadAll endpoint, and also permit instance-wide data exfiltration and destruction by manipulating task attachments through an Insecure Direct Object Reference (IDOR) vulnerability in the GetTaskAttachment endpoint.

Vikunja authorization-bypass idor data-exfiltration data-destruction web-application cve
3t 1c
high advisory

NL Portal IDOR Vulnerability Allows Tampering and Data Leakage of Other Users' Tasks (CVE-2026-49464)

An Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-49464, in NL Portal's Taak V2 implementation (versions 1.5.0 through 3.0.0) allows authenticated attackers to mark other users' tasks as complete, overwrite submitted data, and leak personal information by exploiting an authorization bypass in the `submitTaakV2` GraphQL endpoint.

NL Portal Taak idor graphql data-tampering data-leakage authentication-bypass cve
2t
high advisory

CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference

Authenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace < 2.11.10 wordpress web vulnerability idor privilege-escalation
2t 1c
high advisory

Grackle AI MCP Tool Layer Fail-Open Authorization Leads to IDOR and Privilege Escalation (GHSA-f9ff-5x35-7gfw)

The Grackle AI MCP tool layer, specifically versions of `@grackle-ai/mcp`, `@grackle-ai/plugin-core`, and `@grackle-ai/auth` up to `0.132.1`, suffers from an authorization bypass (IDOR) due to inconsistent inline checks, allowing a compromised scoped agent to perform unauthorized cross-task and cross-session operations, leading to data manipulation, denial of service, and sensitive data disclosure across workspaces.

@grackle-ai/mcp +2 idor authorization-bypass privilege-escalation denial-of-service code-vulnerability software-component
3t
critical advisory

Lemur 1.9.0 Server-Side Request Forgery and IDOR Lead to AWS IAM Compromise

A low-privilege user with a freshly-provisioned SSO account in Netflix's Lemur certificate management service (versions <= 1.9.0) can exploit a Server-Side Request Forgery (SSRF) vulnerability in the ACME authority creation endpoint to reach the AWS EC2 Instance Metadata Service (IMDS), exfiltrating AWS STS credentials, and leveraging a creator-equality Insecure Direct Object Reference (IDOR) vulnerability for permanent access to PKI private keys, resulting in AWS IAM compromise and persistent certificate access.

github.com/Netflix/lemur <= 1.9.0 +2 ssrf idor aws iam pki credential-access exfiltration webserver
2r 5t 5i
high advisory

praisonai-platform: Cross-Workspace Label IDOR Vulnerability

Praison AI's praisonai-platform is vulnerable to an insecure direct object reference (IDOR) in the label endpoints (CVE-2026-47414), allowing cross-workspace label modification and information disclosure due to improper validation of label and issue IDs.

praisonai-platform idor vulnerability privilege-escalation collection impact cloud
2r 3t
critical threat

PraisonAI Platform Cross-Workspace IDOR and Privilege Escalation

PraisonAI Platform is vulnerable to cross-workspace IDOR and member-role privilege escalation, allowing unauthorized users to read, update, or delete resources across workspaces, escalate privileges, and potentially take over accounts and workspaces due to insufficient access controls and role enforcement.

praisonai-platform idor privilege-escalation cross-tenant-access fastapi
3r 5t
high advisory

phpMyFAQ Insecure Direct Object Reference Allows Privilege Escalation (CVE-2026-35671)

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification, leading to privilege escalation.

phpMyFAQ < 4.1.3 idor privilege-escalation web-application
2r 1t 1c
medium advisory

AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.

AudioIgniter plugin for WordPress <= 2.0.2 idor wordpress plugin cve-2026-8679 vulnerability
2r 1t
high advisory

Open WebUI IDOR Vulnerability in Retrieval API Allows Unauthorized Access and Modification of Knowledge Bases

Open WebUI is vulnerable to an IDOR vulnerability in its Retrieval API that bypasses knowledge base access controls, allowing any authenticated user who knows a private knowledge base UUID to read, inject content into, or overwrite another user's knowledge base.

Open WebUI idor authorization_bypass data_manipulation
2r 1t
high advisory

FlowiseAI Cross-Workspace Dataset Takeover via Mass Assignment

FlowiseAI is vulnerable to a mass assignment vulnerability via `Object.assign(entity, body)` which allows a client-controlled `workspaceId` to be overwritten on the Dataset entity, leading to cross-workspace data takeover and IDOR.

flowise mass-assignment cross-workspace idor flowiseai
2r 1t
high advisory

FlowiseAI DatasetRow Mass Assignment Allows Cross-Workspace Data Takeover

FlowiseAI is vulnerable to a mass assignment vulnerability in the DatasetRow controller/service, allowing an authenticated attacker to overwrite the `workspaceId` and `id` of a DatasetRow entity, leading to cross-workspace data takeover and IDOR.

flowise <= 3.1.1 mass-assignment idor cross-workspace
2r 1t
high threat

FlowiseAI Evaluator Cross-Workspace Takeover via Mass Assignment

FlowiseAI is vulnerable to a mass assignment vulnerability in the Evaluator controller/service, where an attacker can manipulate the `workspaceId` during evaluator creation or updates, leading to cross-workspace data takeover and IDOR.

flowise <= 3.1.1 +1 mass-assignment idor privilege-escalation cloud
2r 1t
high advisory

wger IDOR Vulnerability Exposes Private Workout Data (CVE-2026-43977)

wger 2.5 and earlier is vulnerable to CVE-2026-43977, an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to read another user's private workout session notes, exercise history, and training statistics by accessing the `/logs/` and `/stats/` actions on a public template routine they do not own.

wger idor vulnerability data-breach cloud
2r 1t
medium advisory

Cisco Slido Insecure Direct Object Reference Vulnerability

An insecure direct object reference in Cisco Slido's REST API could have allowed an authenticated remote attacker to access social profile data or affect quiz/poll results.

Slido idor cisco credential-access
2r 1t
high advisory

WordPress WCFM Plugin Vulnerable to IDOR Leading to Account Deletion

The WCFM plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) that allows authenticated attackers with Vendor-level access or higher to delete arbitrary users, including administrators.

WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin <= 6.7.25 idor wordpress woocommerce account-deletion
2r 1t 1c
high advisory

Zyosoft School App Insecure Direct Object Reference Vulnerability

Zyosoft's School App contains an Insecure Direct Object Reference vulnerability (CVE-2026-7491) that allows authenticated remote attackers to modify parameters and access or modify other users' data.

School App idor vulnerability web application cve-2026-7491
2r 3t 1c
medium advisory

IBM Langflow Desktop Unauthenticated Image Access via IDOR

IBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an indirect object reference (IDOR) vulnerability (CVE-2026-4503), allowing unauthenticated users to view other users' images due to a user-controlled key.

Langflow Desktop idor vulnerability privilege-escalation
2r 1t 1c
critical advisory

Crafty Controller Users API Insecure Direct Object Reference Vulnerability

Crafty Controller's Users API component contains an insecure direct object reference vulnerability, allowing a remote, authenticated attacker to perform unauthorized user modification actions due to improper API permissions validation (CVE-2026-5652).

idor privilege-escalation cve-2026-5652
2r 1t 1c
critical advisory

Paperclip Cross-Tenant Agent API Key IDOR Vulnerability

A Paperclip API vulnerability allows a board user from one company to create, list, and revoke agent API keys in another company, leading to full cross-tenant compromise due to insufficient authorization checks on `/agents/:id/keys` routes.

idor cross-tenant api paperclip privilege-escalation
3r 5t
high advisory

Chamilo LMS Insecure Direct Object Reference Vulnerability (CVE-2026-32930)

An Insecure Direct Object Reference (IDOR) vulnerability in Chamilo LMS (CVE-2026-32930) allows authenticated teachers to modify gradebook evaluation settings of other courses by manipulating the 'editeval' GET parameter, leading to unauthorized data modification.

idor chamilo lms cve-2026-32930
2r 2t 1c
critical advisory

Amelia WordPress Plugin IDOR Vulnerability CVE-2026-5465

The Amelia WordPress plugin is vulnerable to an insecure direct object reference, allowing authenticated attackers with Provider-level access or higher to escalate privileges and gain persistence by taking over any WordPress account, including Administrator by manipulating the `externalId` field.

wordpress amelia idor privilege-escalation
2r 1t 1c
medium advisory

Brave CMS Insecure Direct Object Reference Vulnerability (CVE-2026-35183)

Brave CMS versions prior to 2.0.6 are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability allowing authenticated users with edit permissions to delete images attached to articles owned by other users due to missing ownership verification in the deleteImage method.

idor brave-cms vulnerability
1r 1t 1c
high advisory

Langflow IDOR Vulnerability Allows Cross-User Flow Manipulation

Langflow versions 1.5.0 and earlier contain an IDOR vulnerability (CVE-2026-34046) that allows authenticated users to read, modify, and delete flows belonging to other users due to a missing ownership check, potentially exposing sensitive information and enabling unauthorized control over AI agent logic.

idor langflow vulnerability
2r 3t
critical advisory

Vikunja Unauthenticated Instance-Wide Data Breach via Link Share and IDOR

Chained authorization flaws in Vikunja allow an unauthenticated attacker to download and delete all file attachments across all projects by disclosing share hashes and exploiting cross-project attachment access.

Vikunja idor privilege-escalation data-breach
2r 6t
high advisory

Amelia Booking WordPress Plugin Insecure Direct Object Reference Vulnerability

The Amelia Booking plugin for WordPress versions 9.1.2 and earlier is vulnerable to Insecure Direct Object References (IDOR), allowing authenticated attackers with customer-level permissions or higher to change user passwords and potentially compromise administrator accounts.

Amelia Booking plugin wordpress plugin idor privilege-escalation CVE-2026-2931
2r 1t
high advisory

Flowise DocumentStore IDOR Vulnerability

A mass assignment vulnerability in the DocumentStore creation endpoint of Flowise allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. By exploiting the implicit UPSERT operation, an attacker can overwrite existing DocumentStore objects, potentially leading to cross-workspace object takeover and broken object-level authorization (IDOR) in multi-tenant deployments.

Flowise idor mass-assignment vulnerability
2r 1t
high advisory

Tutor LMS WordPress Plugin Insecure Direct Object Reference (CVE-2026-3360)

The Tutor LMS plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR), allowing unauthenticated attackers to overwrite billing profiles of users with incomplete orders.

Tutor LMS wordpress plugin idor cve-2026-3360 tutor-lms
2r 2t 1c
high advisory

Aegra Cross-Tenant IDOR in Thread Run Creation

Aegra versions 0.9.0 through 0.9.6 are vulnerable to a cross-tenant IDOR, enabling authenticated users to execute graph runs against other users' threads, read checkpoint states, inject messages, and conceal their actions due to missing user ID validation on run creation endpoints; patched in version 0.9.7.

aegra-api +1 idor privilege-escalation credential-access defense-evasion
2r 3t
high advisory

Download Monitor WordPress Plugin Insecure Direct Object Reference

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) allowing unauthenticated attackers to steal paid digital goods by manipulating PayPal transaction tokens to complete arbitrary orders.

Download Monitor plugin wordpress plugin idor download-monitor cve-2026-3124
2r 1t