Cross-Tenant Privilege Escalation in Shuffle Through 2.2.1 by Shuffle
CVE-2026-92716

8.6HIGH

Key Information:

Vendor

Shuffle

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92716?

The Shuffle Through 2.2.1 version features a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint. This issue allows an administrator to manipulate user IDs to reset and access API keys belonging to non-administrator users in distinct organizations. Consequently, an attacker exploiting this flaw can hijack user accounts across different tenants, compromising the security and integrity of multiple organizations' data.

Affected Version(s)

Shuffle 0 <= 2.2.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.