Insecure Direct Object Reference in APIPark Affecting User Credentials
CVE-2026-108862

6MEDIUM

Key Information:

Vendor

Apiparklab

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108862?

APIPark versions up to 1.9.7-beta are susceptible to an insecure direct object reference vulnerability. This flaw allows authenticated users possessing authorization-view permission to access and read credentials belonging to other applications by manipulating the foreign authorization UUID. By querying the /api/v1/app/authorization endpoint or its related details route, attackers can retrieve sensitive API keys in plaintext, bypassing any credential-hiding mechanisms in place.

Affected Version(s)

APIPark 0 <= 1.9.7-beta

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.