Sceawere
Vulnerability Detail
CVE-2026-108550UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SkillHub Account Merge Authorization Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- iflytek
- Product
- skillhub
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens, roles and namespace ownership.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-10T15:16:58.133Z",
"pubdate": "2026-10-10T15:16:58.133Z",
"executiveSummary": "SkillHub versions prior to 0.2.22 are susceptible to an incorrect authorization vulnerability within the account merging mechanism. This flaw allows an authenticated attacker to perform a complete account takeover by manipulating the merge workflow to link their own account with a target's identity. The vulnerability resides in the AccountMergeService and AccountMergeController, which fail to properly validate ownership or authorization when initiating and confirming merge requests. By exploiting this, an attacker can gain unauthorized access to a victim's API tokens, elevated roles, and namespace ownership. This represents a critical security failure, as it enables lateral movement and privilege escalation within the platform. The attack requires the adversary to be an authenticated user of the application, but it does not necessitate any further interaction from the victim. The impact is total account compromise, potentially allowing the attacker to perform administrative actions, access sensitive user data, and manipulate private resources owned by the target account.",
"technicalDetails": "The vulnerability originates from a failure in the logical access control implementation within the AccountMergeService and AccountMergeController components of SkillHub. In the affected versions (prior to 0.2.22), the application fails to enforce strict authorization checks during the account merge process, specifically at the initiation and confirmation stages.\nThe exploitation flow begins when an authenticated attacker targets a victim's account via a username or associated OAuth identity. The attacker interacts with the merge initiation endpoint provided by the AccountMergeController. Due to the lack of server-side verification ensuring that the initiator is authorized to link the specified target account, the application improperly processes the request.\nDuring the initiation phase, the system generates a verification token. In the vulnerable implementation, the application returns this token directly to the attacker in the response body or through an insecure communication channel, rather than sending it exclusively to the legitimate owner of the target account. This design flaw allows the attacker to obtain the necessary secret required to finalize the link.\nUpon receiving the verification token, the attacker proceeds to the merge confirmation endpoint. By submitting the token, the attacker forces the system to complete the linkage between their own account and the victim's account. This association causes the attacker's account to inherit the full authorization context of the victim.\nPost-exploitation, the attacker gains complete access to the target's account privileges. This includes, but is not limited to, the victim's active API tokens, custom user roles, and full administrative or ownership rights over the victim's namespaces. The attacker effectively assumes the identity and permissions of the target user, allowing for persistent unauthorized access to the application's resources and data. The vulnerability is exploitable by any authenticated user, requiring no additional social engineering or victim interaction, as the system provides the required verification secret directly to the initiator of the request."
}