๐Ÿ” CVE Alert

CVE-2026-108855

MEDIUM 5.4

UnicomAI Wanwu through 0.6.5 Missing Authorization via DELETE /v1/appspace/app/publish

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. Attackers can supply a target appId and appType from the exploration marketplace to delete other users' api_key rows across organizations, cutting off MCP and OpenAPI client access.

CWE CWE-862
Vendor unicomai
Product wanwu
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unicomai wanwu

Be the first to know when new medium vulnerabilities affecting unicomai wanwu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

UnicomAI / Wanwu
0 โ‰ค 0.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/unicomai-wanwu-unpublish-revokes-consumer-appkeys github.com: https://github.com/UnicomAI/wanwu/blob/v0.6.5/internal/app-service/client/orm/app.go#L48-L68 github.com: https://github.com/UnicomAI/wanwu vulncheck.com: https://www.vulncheck.com/advisories/unicomai-wanwu-through-0.6.5-missing-authorization-via-delete-v1-appspace-app-publish

Credits

hieuPenguinnn