Insecure Direct Object Reference in 1millionbot Millie Chat
CVE-2026-4400

7HIGH

Key Information:

Vendor
CVE Published:
31 March 2026

What is CVE-2026-4400?

An Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot's Millie Chat allows unauthorized viewing of private conversations. This security flaw arises from the endpoint 'api.1millionbot.com/api/public/conversations/', where an attacker can access another user's confidential communications simply by altering the conversation ID. Exploitation of this vulnerability does not require user credentials or impersonation, posing a substantial risk to user privacy and data integrity. Protecting against this vulnerability is crucial to safeguarding sensitive information and maintaining trust in chat applications.

Affected Version(s)

Millie chat 3.6.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David UtĂłn Amaya (m3n0sd0n4ld)
.