Common Weakness Enumeration

    CWE Definition / CWE-639

    CWE-639: Authorization Bypass Through User-Controlled Key

    The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

    Published:30 Jan 2008
    Organization:MITRE
    Modified:30 Apr 2026

    Related Weakness

    CWE-863: Incorrect Authorization

    CWE-863: Incorrect Authorization

    CWE-284: Improper Access Control