๐Ÿ” CVE Alert

CVE-2026-108853

HIGH 8.1

UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying their appId. Attackers can send requests to DELETE /v1/appspace/app with guessed sequential assistant IDs to permanently delete victims' applications, workflows, conversations, and associated data.

CWE CWE-639
Vendor unicomai
Product wanwu
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unicomai wanwu

Be the first to know when new high vulnerabilities affecting unicomai wanwu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

UnicomAI / Wanwu
0 < 0.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/unicomai-wanwu-appspace-cross-owner-delete github.com: https://github.com/UnicomAI/wanwu/blob/v0.6.2/internal/bff-service/service/appspace.go#L20-L58 github.com: https://github.com/UnicomAI/wanwu/commit/13d0b225ec237d5a0b44730b2331efadaeb462a2 github.com: https://github.com/UnicomAI/wanwu/releases/tag/v0.6.3 github.com: https://github.com/UnicomAI/wanwu vulncheck.com: https://www.vulncheck.com/advisories/unicomai-wanwu-before-0.6.3-idor-via-delete-v1-appspace-app

Credits

hieuPenguinnn