Insecure Direct Object Reference in UnicomAI Wanwu Affects Application Management
CVE-2026-108853

7.2HIGH

Key Information:

Vendor

Unicomai

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108853?

UnicomAI Wanwu prior to version 0.6.3 is susceptible to an insecure direct object reference vulnerability. This flaw allows authenticated low-privileged users to delete applications, workflows, conversations, and their associated data belonging to other tenants. By manipulating the appId, users can exploit the DELETE request to /v1/appspace/app, thereby executing unauthorized deletions of critical application components. It is crucial for organizations using this software to implement the necessary patches to safeguard against potential data loss and disruption.

Affected Version(s)

Wanwu 0 < 0.6.3

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.