Cross-Tenant Privilege Escalation in Shuffle Through 2.2.1 by Shuffle
CVE-2026-92716
8.6HIGH
What is CVE-2026-92716?
The Shuffle Through 2.2.1 version features a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint. This issue allows an administrator to manipulate user IDs to reset and access API keys belonging to non-administrator users in distinct organizations. Consequently, an attacker exploiting this flaw can hijack user accounts across different tenants, compromising the security and integrity of multiple organizations' data.
Affected Version(s)
Shuffle 0 <= 2.2.1
