๐Ÿ” CVE Alert

CVE-2026-108854

MEDIUM 5.4

Wanwu before 0.6.3 IDOR AppKey Deletion via DELETE /v1/appspace/app/key

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers can iterate sequential key IDs against DELETE /v1/appspace/app/key to revoke AppKeys across organizations, breaking MCP and OpenAPI clients until owners issue new keys.

CWE CWE-639
Vendor unicomai
Product wanwu
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unicomai wanwu

Be the first to know when new medium vulnerabilities affecting unicomai wanwu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

UnicomAI / Wanwu
0 < 0.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/unicomai-wanwu-appkey-delete-id-bola github.com: https://github.com/UnicomAI/wanwu/blob/v0.6.2/internal/app-service/client/orm/app_key.go#L26-L31 github.com: https://github.com/UnicomAI/wanwu/commit/13d0b225ec237d5a0b44730b2331efadaeb462a2 github.com: https://github.com/UnicomAI/wanwu/releases/tag/v0.6.3 github.com: https://github.com/UnicomAI/wanwu vulncheck.com: https://www.vulncheck.com/advisories/wanwu-before-0.6.3-idor-appkey-deletion-via-delete-v1-appspace-app-key

Credits

hieuPenguinnn