<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Idor — PoC Archive</title><link>https://poc.intelseclab.com/tags/idor/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 19 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/idor/index.xml" rel="self" type="application/rss+xml"/><item><title>Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-55255 (GHSA-qrpv-q767-xqq2). Status: Weaponized — confirmed cross-user flow execution via a minimal request-only PoC. Affects: Langflow — open-source platform for building and deploying AI-powered agents and workflows (langflow-ai/langflow), OpenAI-compatible Responses API. Tags: langflow, ai-agent-framework, idor, cwe-639, authenticated, remote, cross-tenant, kev.</description><category>web</category><category>High</category><category>langflow</category><category>ai-agent-framework</category><category>idor</category><category>cwe-639</category><category>authenticated</category><category>remote</category><category>cross-tenant</category><category>kev</category></item><item><title>WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39676-wordpress-download-manager-idor/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39676-wordpress-download-manager-idor/</guid><description>Medium severity — web · CVE-2026-39676. Status: PoC. Affects: Download Manager plugin for WordPress. Tags: wordpress, wordpress-plugin, idor, missing-authorization, unauthenticated, download-manager.</description><category>web</category><category>Medium</category><category>wordpress</category><category>wordpress-plugin</category><category>idor</category><category>missing-authorization</category><category>unauthenticated</category><category>download-manager</category></item><item><title>Vaultwarden Organization Collection Permissions Bypass &amp; Cipher Enumeration (CVE-2026-26012)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26012-vaultwarden-collection-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26012-vaultwarden-collection-bypass/</guid><description>Medium severity (CVSS 6.5) — web · CVE-2026-26012 (GHSA-h265-g7rm-h337). Status: PoC. Affects: Vaultwarden (unofficial Bitwarden-compatible server). Tags: vaultwarden, bitwarden, password-manager, idor, access-control-bypass, api, cipher-enumeration, self-hosted.</description><category>web</category><category>Medium</category><category>vaultwarden</category><category>bitwarden</category><category>password-manager</category><category>idor</category><category>access-control-bypass</category><category>api</category><category>cipher-enumeration</category><category>self-hosted</category></item><item><title>Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24136-saleor-graphql-idor/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24136-saleor-graphql-idor/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-24136. Status: PoC. Affects: Saleor e-commerce platform (GraphQL API). Tags: saleor, graphql, idor, bola, cwe-639, pii-leak, unauthenticated, e-commerce.</description><category>web</category><category>High</category><category>saleor</category><category>graphql</category><category>idor</category><category>bola</category><category>cwe-639</category><category>pii-leak</category><category>unauthenticated</category><category>e-commerce</category></item><item><title>Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40776-eventin-broken-access-control/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40776-eventin-broken-access-control/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-40776 / Patchstack PSID 85de025d71e7. Status: PoC. Affects: Eventin — Events Calendar, Event Booking, Ticket &amp; Registration (wp-event-solution WordPress plugin). Tags: wordpress, wordpress-plugin, broken-access-control, idor, nonce-misuse, cwe-862, pii-disclosure, unauthenticated.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-plugin</category><category>broken-access-control</category><category>idor</category><category>nonce-misuse</category><category>cwe-862</category><category>pii-disclosure</category><category>unauthenticated</category></item><item><title>AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30950-autogpt-session-idor/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30950-autogpt-session-idor/</guid><description>High severity (CVSS 7.1) — web · CVE-2026-30950 (GHSA-q58p-v9r9-7gqj). Status: PoC. Affects: AutoGPT Platform (autogpt-platform-backend, chat/copilot feature). Tags: autogpt, idor, cwe-862, session-hijack, missing-authorization, python, fastapi, redis.</description><category>web</category><category>High</category><category>autogpt</category><category>idor</category><category>cwe-862</category><category>session-hijack</category><category>missing-authorization</category><category>python</category><category>fastapi</category><category>redis</category></item></channel></rss>