CVE-2026-108581
Octop through 1.0.2b6 Missing Authorization Exposes Provider API Keys via /api/providers
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/voice/providers. Attackers can query these endpoints, which only validate the JWT, to obtain plaintext LLM and voice provider API keys and abuse the upstream provider accounts.
| CWE | CWE-862 |
| Vendor | tencentcloud |
| Product | octop |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for tencentcloud octop
Be the first to know when new medium vulnerabilities affecting tencentcloud octop are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
TencentCloud / Octop
0 โค 1.0.2b6
References
github.com: https://github.com/TencentCloud/Octop/pull/1507 github.com: https://github.com/TencentCloud/Octop/pull/1265 hackmd.io: https://hackmd.io/@haind/octop-provider-key-cross-role-read github.com: https://github.com/TencentCloud/Octop/blob/eb28011249c02cafd389b2d424294c6c1b9cf422/src/octop/api/routers/providers.py#L120-L208 vulncheck.com: https://www.vulncheck.com/advisories/octop-through-1.0-2b6-missing-authorization-exposes-provider-api-keys-via-api-providers
Credits
ra-co88 HaiND from the Post and Telecommunication Institute of Technology