Insecure Direct Object Reference in APIPark Affecting User Credentials
CVE-2026-108862
6MEDIUM
What is CVE-2026-108862?
APIPark versions up to 1.9.7-beta are susceptible to an insecure direct object reference vulnerability. This flaw allows authenticated users possessing authorization-view permission to access and read credentials belonging to other applications by manipulating the foreign authorization UUID. By querying the /api/v1/app/authorization endpoint or its related details route, attackers can retrieve sensitive API keys in plaintext, bypassing any credential-hiding mechanisms in place.
Affected Version(s)
APIPark 0 <= 1.9.7-beta
