CVE-2026-108856
UnicomAI Wanwu through 0.6.5 Authorization Bypass via /v1/appspace/app/key AppKey Minting
CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th
UnicomAI Wanwu through 0.6.5 contains an authorization bypass vulnerability that allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers supplying a victim's MCP server UUID with appType mcpserver can open MCP sessions and invoke the server's tools using the victim's upstream authentication.
| CWE | CWE-639 |
| Vendor | unicomai |
| Product | wanwu |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unicomai wanwu
Be the first to know when new medium vulnerabilities affecting unicomai wanwu are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
UnicomAI / Wanwu
0 โค 0.6.5
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/unicomai-wanwu-mcp-key-arbitrary-resource github.com: https://github.com/UnicomAI/wanwu/blob/v0.6.5/internal/app-service/client/orm/app_key.go#L37-L49 github.com: https://github.com/UnicomAI/wanwu/blob/v0.6.5/internal/bff-service/server/http/middleware/auth_openapi.go#L46-L70 github.com: https://github.com/UnicomAI/wanwu vulncheck.com: https://www.vulncheck.com/advisories/unicomai-wanwu-through-0.6.5-authorization-bypass-via-v1-appspace-app-key-appkey-minting
Credits
hieuPenguinnn