On this page

CWE-639: Authorization Bypass Through User-Controlled Key

Weakness Summary

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

  • Canonical source: MITRE CWE-639 (opens in a new tab)
  • Published Atomicorp CVE observations: 10
  • Distinct affected products in those observations: 10
  • Active Atomicorp rules associated with this weakness: 34

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and crlemurAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokployAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2021-45428Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Uploadtlr-2005kshAttack Blocked by Atomicorp392301
CVE-2025-14998Branda WordPress plugin - Privilege EscalationBranda – White Label & Branding, Free Login Page CustomizerDetected by Atomicorp377360
CVE-2014-8356ZHONE < S3.0.501 - Multiple Vulnerabilitiesznid 2426a firmwareAttack Blocked by Atomicorp390726 , 392301 , 392647 , 392648
CVE-2026-47743Shopper: Multiple data integrity and disclosure issues in admin Livewire componentsshopperAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret ExfiltrationFlowiseAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-10493Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via CookieChained QuizAttack Blocked by Atomicorp390726 , 392647
CVE-2026-45551Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting WritegroupofficeAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73657Trigger.dev: Cross-tenant payload poisoning via packet write + replaytrigger.devAttack Blocked by Atomicorp347009

Associated Atomicorp WAF Rules

RuleStatusBehavior
333140Activedisruptive (deny)
333141Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
340014Activedisruptive (deny)
340029Activedisruptive (deny)
340095Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
377360Activenon-disruptive (pass)
390722Activedisruptive (deny)
390726Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
398021Activedisruptive (deny)
398022Activedisruptive (deny)