目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-639 通过用户控制密钥绕过授权机制 类漏洞列表 2041

CWE-639 通过用户控制密钥绕过授权机制 类弱点 2041 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-639 属于授权绕过漏洞,指系统依赖用户可控的键值检索数据时,未验证该键值是否属于当前请求用户。攻击者通过篡改标识符(如ID),直接访问其他用户的数据记录。开发者应避免使用直接暴露的键值,转而采用间接引用或会话上下文验证,确保每次数据访问前严格校验资源归属权,从而防止越权访问。

MITRE CWE 官方描述
CWE:CWE-639 通过用户可控密钥绕过授权(Authorization Bypass Through User-Controlled Key) 英文:系统的授权功能未能阻止用户通过修改标识数据的密钥值,从而获取其他用户的数据或记录。 系统中基于某个受用户控制的密钥值来检索用户记录。该密钥通常用于标识系统中存储的与用户相关的记录,并用于查找该记录以呈现给用户。攻击者很可能需要是系统中的已认证用户。然而,授权过程未能正确检查数据访问操作,以确保执行该操作的已认证用户拥有执行所请求数据访问的足够权限,从而绕过了系统中存在的任何其他授权检查。例如,攻击者可以查看检索特定用户数据的位置(例如搜索界面),并确定正在查找的项目的密钥是否可外部控制。该密钥可能是 HTML 表单中的隐藏字段,也可能作为 URL 参数或未加密的 Cookie 变量传递,在这些情况下,都有可能篡改密钥值。这种弱点的一种表现形式是,当系统使用顺序生成或易于猜测的会话 ID(Session IDs)时,允许一个用户轻松切换到另一个用户的会话并读取/修改其数据。
常见影响 (3)
Access Control Bypass Protection Mechanism
Access control checks for specific user data or functionality can be bypassed.
Access Control Gain Privileges or Assume Identity
Horizontal escalation of privilege is possible (one user can view/modify information of another user).
Access Control Gain Privileges or Assume Identity
Vertical escalation of privilege is possible if the user-controlled key is actually a flag that indicates administrator status, allowing the attacker to gain administrative access.
缓解措施 (3)
Architecture and Design For each and every data access, ensure that the user has sufficient privilege to access the record that is being requested.
Architecture and Design, Implementation Make sure that the key that is used in the lookup of a specific user's record is not controllable externally by the user or that any tampering can be detected.
Architecture and Design Use encryption in order to make it more difficult to guess other legitimate values of the key or associate a digital signature with the key so that the server can verify that there has been no tampering.
代码示例 (1)
The following code uses a parameterized statement, which escapes metacharacters and prevents SQL injection vulnerabilities, to construct and execute a SQL query that searches for an invoice matching the specified identifier [1]. The identifier is selected from a list of all invoices associated with the current authenticated user.
... conn = new SqlConnection(_ConnectionString); conn.Open(); int16 id = System.Convert.ToInt16(invoiceID.Text); SqlCommand query = new SqlCommand( "SELECT * FROM invoices WHERE id = @id", conn); query.Parameters.AddWithValue("@id", id); SqlDataReader objReader = objCommand.ExecuteReader(); ...
Bad · C#
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-97721 Sanluan PublicCMS 导出功能越权漏洞 — PublicCMS 2.7 Low 2026-09-25
CVE-2026-97647 学生管理系统 editLog.php 授权绕过漏洞 — student-management-system 5.3 Medium 2026-09-25
CVE-2026-97646 ningzichun 学生管理系统 getStudent.php 权限绕过漏洞 — student-management-system 7.3 High 2026-09-25
CVE-2026-97636 Apache Airflow HashiCorp Provider 密钥绕过漏洞 — Apache Airflow HashiCorp provider - - 2026-09-24
CVE-2026-97368 SpringBlade 用户认证信息接口越权漏洞 — SpringBlade 6.3 Medium 2026-09-24
CVE-2026-48073 Docmost 页面导出可包含受限附件漏洞 — docmost 4.3 Medium 2026-09-24
CVE-2026-52850 Docmost transclusion查找API越权漏洞 — docmost 4.3 Medium 2026-09-24
CVE-2026-77293 TREK 越权删除笔记文件漏洞 — TREK 7.1 High 2026-09-24
CVE-2026-79759 Termix部署端点跨用户信息泄露漏洞 — Termix 4.3 Medium 2026-09-24
CVE-2026-78310 DIAEnergie 授权绕过漏洞 — DIAEnergie 4.3 Medium 2026-09-24
CVE-2026-87739 PaperCut MF/NG 报告生成时未评估用户权限 — PaperCut NG/MF 6.9 Medium 2026-09-24
CVE-2026-96762 Mooncake RPC路径卸载段授权漏洞 — mooncake 7.3 High 2026-09-23
CVE-2026-84720 Automation Controller 祖先工件缺少防止搜索,通过ORM遍历暴露no_log设置的统计信息 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 6.5 Medium 2026-09-23
CVE-2026-84713 自动化控制器通知收件人密钥泄露漏洞 — Red Hat Ansible Automation Platform 2.7 6.5 Medium 2026-09-23
CVE-2026-76087 Formie 未授权提交覆盖漏洞 — formie 8.2 High 2026-09-23
CVE-2026-95602 YITH WooCommerce请求报价插件4.46.1前IDOR漏洞 — YITH WooCommerce Request A Quote 6.5 Medium 2026-09-23
CVE-2026-95592 WordPress Team插件6.0.0前直接对象引用漏洞 — Team 5.3 Medium 2026-09-23
CVE-2026-93623 WordPress AI Engine 插件不安全直接对象引用漏洞 — AI Engine 5.3 Medium 2026-09-23
CVE-2026-93513 SiteSkite插件2.1.7版本IDOR漏洞 — SiteSkite 4.3 Medium 2026-09-23
CVE-2026-92419 WEBCON BPS 不安全的直接对象引用漏洞 — WEBCON BPS 5.3 Medium 2026-09-23
CVE-2026-55610 InvoiceShelf跨租户IDOR致账户接管漏洞 — InvoiceShelf 8.7 High 2026-09-23
CVE-2026-86678 认证缺陷漏洞 — ManageEngine Applications Manager 8.8 High 2026-09-23
CVE-2026-84789 访问控制失效漏洞 — ManageEngine OpManager 7.1 High 2026-09-23
CVE-2026-84791 访问控制缺陷漏洞 — ManageEngine OpManager 7.1 High 2026-09-23
CVE-2026-96271 Photoview 2.4.0 授权绕过漏洞 — photoview 7.1 High 2026-09-23
CVE-2026-75101 GitHub Enterprise Server 授权绕过致私有拉取差异泄露 — Enterprise Server 6.0 Medium 2026-09-22
CVE-2026-77426 Unleash 管理接口缺失await导致权限检查失败 — unleash 7.1 High 2026-09-22
CVE-2026-77425 Unleash 项目成员跨项目篡改激活策略漏洞 — unleash 4.3 Medium 2026-09-22
CVE-2026-76910 Unleash 克隆功能越权复制漏洞 — unleash 5.3 Medium 2026-09-22
CVE-2026-94462 Spree 关联购物车接口权限控制不当漏洞 — spree 7.1 High 2026-09-22

CWE-639(通过用户控制密钥绕过授权机制) 是常见的弱点类别,本平台收录该类弱点关联的 2041 条 CVE 漏洞。