authorization-bypass 9
- GraphQL Role Parameter Abuse Leads to Restricted Medical Note Disclosure | Clearance
- IDOR – Unauthorized Grant Approval via Workflow Manipulation | Briarcliff Foundation
- Next.js Middleware Authorization Bypass (CVE-2025-29927) | BugVault
- IDOR via WebSocket Subscription – Cross-Order Data Exposure | JoyStick
- IDOR via Sequential Order IDs | Cheesy Does It
- Broken Access Control – Admin Access Token Brute Force Leads to Unauthorized Admin Access | Gift List
- Broken Access Control – Privilege Escalation via Client-Controlled Cookie | Privilege Escalation via Client-Controlled Cookie
- Broken Access Control – Unprotected Admin Panel via Unpredictable URL Leading to Privilege Escalation | Unprotected Admin Panel
- Broken Access Control – Unprotected Admin Functionality Leading to Privilege Escalation | Unprotected Admin Functionality