CVE-2026-108581
Received Received - Intake

TencentCloud Octop API Key Exposure via Missing Authorization

Vulnerability report for CVE-2026-108581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/voice/providers. Attackers can query these endpoints, which only validate the JWT, to obtain plaintext LLM and voice provider API keys and abuse the upstream provider accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TencentCloud Octop 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108581 is a missing authorization vulnerability in TencentCloud Octop through version 1.0.2b6. It allows authenticated low-privileged users to read stored provider API keys via endpoints like GET /api/providers and GET /api/voice/providers. These endpoints only validate the JWT token but do not check user permissions, exposing plaintext LLM and voice provider API keys.

Detection Guidance

Check if GET /api/providers or GET /api/voice/providers endpoints return plaintext API keys. Use curl commands like: curl -H 'Authorization: Bearer <JWT>' http://<target>/api/providers or curl -H 'Authorization: Bearer <JWT>' http://<target>/api/voice/providers. If keys are exposed, the system is vulnerable.

Impact Analysis

Attackers with valid but non-admin JWT tokens can exploit this to retrieve all provider API keys and abuse upstream provider accounts. This could lead to unauthorized access to external LLM services, potential data breaches, or misuse of paid services. The impact is higher in multi-user deployments where non-admin users can access centralized credentials.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access controls. Exposing API keys could lead to unauthorized data access or processing, breaching GDPR's data protection principles or HIPAA's safeguards for protected health information. Organizations may face legal penalties or reputational damage.

Mitigation Strategies

Upgrade Octop to a patched version (e.g., via PR #1265 or #1507). If immediate upgrade is not possible, restrict access to /api/providers and /api/voice/providers endpoints or implement credential masking manually.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart