Authorization Bypass Vulnerability in UnicomAI Wanwu by UnicomAI
CVE-2026-108856
2.3LOW
What is CVE-2026-108856?
UnicomAI Wanwu versions up to 0.6.5 are susceptible to an authorization bypass vulnerability that allows authenticated users to generate AppKeys intended for other users' MCP servers. By exploiting this flaw, attackers can send a POST request to /v1/appspace/app/key with the UUID of a victim's MCP server and the appropriate appType, thereby gaining access to the victim’s upstream authentication. This opens up potential unauthorized control over MCP sessions and their associated tools, posing significant risks to server integrity and user data.
Affected Version(s)
Wanwu 0 <= 0.6.5
