#IDOR
All CosmicBytez Labs articles tagged #IDOR, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-16310: MemberDash WordPress Plugin Unauthenticated Account Takeover
MemberDash ≤ 1.8.5 has an IDOR letting unauthenticated attackers change any WordPress user's password via a crafted registration request.
- Security
CVE-2026-53546: Termix WebSocket Host Bypass Grants Cross-User SSH Access
Termix terminal WebSocket accepts attacker-controlled host IDs without ownership checks, enabling cross-user SSH access to any managed server. CVSS 9.6.
- Security
CVE-2026-53548: Termix IDOR Exposes All Stored SSH Passwords to Any User
Termix's password endpoint returns decrypted SSH credentials for any host ID without ownership verification, exposing all stored passwords. CVSS 9.6.
- Security
CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE
A critical CVSS 9.1 vulnerability in SolarWinds Serv-U allows group administrators to exploit an insecure direct object reference flaw to escalate...
- Security
Coolify CVE-2026-34037: CVSS 9.9 IDOR Enables Cross-Team Resource Takeover
A critical IDOR vulnerability in Coolify's cloneTo() Livewire action allows authenticated users to clone and take over resources across team boundaries...
- News
Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk
Security researchers discovered multi-tenant isolation failures in the Dify AI platform that allowed attackers to read private conversations from other...
- Security
CVE-2026-53470: migration-planner IDOR Exposes Cross-Tenant S3 Pre-Signed URLs
A critical improper access control vulnerability (CVSS 9.6) in Red Hat's migration-planner allows an authenticated attacker to bypass ownership checks and...
- Security
CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access
A critical insecure direct object reference vulnerability allows authenticated users to pivot to any other user's profile by modifying an id parameter in...
- Security
CVE-2026-4896: WCFM WooCommerce Plugin IDOR Allows
A high-severity Insecure Direct Object Reference vulnerability in the WCFM Frontend Manager for WooCommerce plugin (up to v6.7.25) lets authenticated...