Authorization Bypass Vulnerability in UnicomAI Wanwu by UnicomAI
CVE-2026-108856

2.3LOW

Key Information:

Vendor

Unicomai

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108856?

UnicomAI Wanwu versions up to 0.6.5 are susceptible to an authorization bypass vulnerability that allows authenticated users to generate AppKeys intended for other users' MCP servers. By exploiting this flaw, attackers can send a POST request to /v1/appspace/app/key with the UUID of a victim's MCP server and the appropriate appType, thereby gaining access to the victim’s upstream authentication. This opens up potential unauthorized control over MCP sessions and their associated tools, posing significant risks to server integrity and user data.

Affected Version(s)

Wanwu 0 <= 0.6.5

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.