Missing Authorization Vulnerability in UnicomAI Wanwu Product
CVE-2026-108855
5.3MEDIUM
What is CVE-2026-108855?
UnicomAI Wanwu through version 0.6.5 is susceptible to a missing authorization vulnerability, allowing authenticated users to revoke AppKeys belonging to other users through the unpublish endpoint. Attackers can exploit this flaw to provide a target appId and appType from the exploration marketplace and delete api_key records across organizations. This malicious action effectively cuts off access for various clients using the MCP and OpenAPI, posing a significant risk to application security.
Affected Version(s)
Wanwu 0 <= 0.6.5
