Insecure Direct Object Reference in Wanwu by UnicomAI
CVE-2026-108854

5.3MEDIUM

Key Information:

Vendor

Unicomai

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108854?

Wanwu versions prior to 0.6.3 are susceptible to an insecure direct object reference vulnerability, enabling authenticated users to delete legacy AppKeys belonging to other users. By manipulating the numeric apiId parameter, attackers can sequentially revoke AppKeys through the DELETE /v1/appspace/app/key endpoint. This exploitation can severely disrupt operations for clients relying on the MCP and OpenAPI integrations until new keys are reissued by the respective owners.

Affected Version(s)

Wanwu 0 < 0.6.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.