CVE-2026-108862
APIPark through 1.9.7-beta IDOR via application authorization endpoints
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential.
| CWE | CWE-639 |
| Vendor | apiparklab |
| Product | apipark |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for apiparklab apipark
Be the first to know when new medium vulnerabilities affecting apiparklab apipark are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
APIParkLab / APIPark
0 โค 1.9.7-beta
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/apipark-cross-app-authorization-uuid github.com: https://github.com/APIParkLab/APIPark/blob/v1.9.7-beta/module/application-authorization/iml.go#L451-L511 github.com: https://github.com/APIParkLab/APIPark vulncheck.com: https://www.vulncheck.com/advisories/apipark-through-1.9.7-beta-idor-via-application-authorization-endpoints
Credits
hieuPenguinnn