Medium severity5.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108862
CVE-2026-108862
Description
APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.9.7-beta
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.