CVE-2026-108854
Received Received - Intake

Wanwu Insecure Direct Object Reference Allows AppKey Deletion

Vulnerability report for CVE-2026-108854, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers can iterate sequential key IDs against DELETE /v1/appspace/app/key to revoke AppKeys across organizations, breaking MCP and OpenAPI clients until owners issue new keys.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
UnicomAI Wanwu 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Wanwu before version 0.6.3 has an insecure direct object reference vulnerability. This allows any authenticated user with enabled privileges to delete other users' legacy AppKeys by providing a numeric API ID. Attackers can exploit this by iterating sequential key IDs against the DELETE /v1/appspace/app/key endpoint to revoke AppKeys across organizations.

Detection Guidance

Check for unauthorized DELETE requests to /v1/appspace/app/key endpoints with sequential apiId values. Monitor logs for repeated failed or successful deletions of AppKeys by non-admin users.

Impact Analysis

This vulnerability can disrupt services relying on AppKeys, such as MCP and OpenAPI clients. Users may experience broken functionality until new keys are issued by the owners. It can lead to unauthorized deletion of critical access keys and potential service outages.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized deletion of API keys, which may lead to unauthorized access to sensitive data or disruption of services. Under GDPR, unauthorized access or deletion of user data could violate principles of data integrity and security. For HIPAA, if the affected system handles protected health information, unauthorized deletion of keys could compromise access controls and integrity of ePHI.

Mitigation Strategies

Upgrade Wanwu to version 0.6.3 or later. Review and revoke any compromised AppKeys. Restrict DELETE permissions to authorized users only. Implement rate limiting on key deletion endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108854. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart