Insecure Direct Object Reference in Wanwu by UnicomAI
CVE-2026-108854
5.3MEDIUM
What is CVE-2026-108854?
Wanwu versions prior to 0.6.3 are susceptible to an insecure direct object reference vulnerability, enabling authenticated users to delete legacy AppKeys belonging to other users. By manipulating the numeric apiId parameter, attackers can sequentially revoke AppKeys through the DELETE /v1/appspace/app/key endpoint. This exploitation can severely disrupt operations for clients relying on the MCP and OpenAPI integrations until new keys are reissued by the respective owners.
Affected Version(s)
Wanwu 0 < 0.6.3
