VYPR

APIPark

by APIParkLab

CVEs (1)

  • CVE-2026-108862MedOct 11, 2026
    risk 0.34cvss 5.3epss —

    APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query…