VYPR
Medium severity5.4NVD Advisory· Published Oct 11, 2026

CVE-2026-108854

CVE-2026-108854

Description

Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers can iterate sequential key IDs against DELETE /v1/appspace/app/key to revoke AppKeys across organizations, breaking MCP and OpenAPI clients until owners issue new keys.

Affected products

2
  • UnicomAI/Wanwureferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <0.6.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.