CVE-2026-108550
Received Received - Intake

Incorrect Authorization in SkillHub Allows Account Takeover via Merge Flow

Vulnerability report for CVE-2026-108550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens, roles and namespace ownership.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek skillhub 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SkillHub before version 0.2.22 allows authenticated attackers to take over other accounts by exploiting an incorrect authorization flaw in the account merge process. Attackers can initiate a merge with a target username or OAuth identity, receive a verification token directly, and confirm the merge to inherit the victim's API tokens, roles, and namespace ownership without the victim's consent.

Detection Guidance

Check SkillHub logs for unusual account merge activities, especially failed or successful merges between unrelated accounts. Look for API calls to /merge endpoints with unexpected username or OAuth identity parameters. Verify if verification tokens are being sent to attacker-controlled channels instead of the target account owner.

Impact Analysis

If you use SkillHub before version 0.2.22, an attacker could gain full control of your account by exploiting this flaw. They would inherit your API tokens, roles, and namespace ownership, potentially accessing sensitive data, performing unauthorized actions, or taking over your organization's resources. The attack requires only your username or a known OAuth identity.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized disclosures, or loss of control over protected health information, potentially leading to legal penalties and compliance failures.

Mitigation Strategies

Upgrade SkillHub to version 0.2.22 or later immediately. Disable account merge functionality if not required. Implement strict monitoring for merge operations and revoke all API tokens after merges. Review recent merges for signs of unauthorized activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart