CVE-2026-108855
UnicomAI Wanwu through 0.6.5 Missing Authorization via DELETE /v1/appspace/app/publish
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. Attackers can supply a target appId and appType from the exploration marketplace to delete other users' api_key rows across organizations, cutting off MCP and OpenAPI client access.
| CWE | CWE-862 |
| Vendor | unicomai |
| Product | wanwu |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unicomai wanwu
Be the first to know when new medium vulnerabilities affecting unicomai wanwu are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
UnicomAI / Wanwu
0 โค 0.6.5
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/unicomai-wanwu-unpublish-revokes-consumer-appkeys github.com: https://github.com/UnicomAI/wanwu/blob/v0.6.5/internal/app-service/client/orm/app.go#L48-L68 github.com: https://github.com/UnicomAI/wanwu vulncheck.com: https://www.vulncheck.com/advisories/unicomai-wanwu-through-0.6.5-missing-authorization-via-delete-v1-appspace-app-publish
Credits
hieuPenguinnn