CVE-2026-108862
Received Received - Intake

Insecure Direct Object Reference in APIPark Exposes Credentials

Vulnerability report for CVE-2026-108862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
APIParkLab APIPark 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

APIPark through version 1.9.7-beta has an insecure direct object reference vulnerability. Authenticated users with specific permissions can read other applications' credentials by providing a foreign authorization UUID. This allows querying routes like /api/v1/app/authorization to retrieve plaintext API keys even if HideCredential is enabled.

Detection Guidance

To detect this vulnerability, monitor APIPark logs for unauthorized access to /api/v1/app/authorization or its details routes. Check for queries using foreign authorization UUIDs by authenticated users with authorization-view permission. Look for plaintext API key exposure in responses.

Impact Analysis

Attackers with authorization-view permission on one application could exploit this to access plaintext API keys of other applications. This could lead to unauthorized access to sensitive data, potential data breaches, or misuse of API resources across different applications.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It may result in non-compliance due to data exposure, lack of proper access controls, and failure to protect personal or health information as mandated by these regulations.

Mitigation Strategies

Immediately update APIPark to the latest version beyond 1.9.7-beta. Restrict authorization-view permissions to only necessary users. Disable direct object reference in API routes by implementing proper access controls and input validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart