Sceawere

Vulnerability Detail

CVE-2026-108581UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TencentCloud Octop API Key Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
TencentCloud
Product
Octop
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/voice/providers. Attackers can query these endpoints, which only validate the JWT, to obtain plaintext LLM and voice provider API keys and abuse the upstream provider accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-10T16:16:31.380Z",
  "pubdate": "2026-10-10T16:16:31.380Z",
  "executiveSummary": "The vulnerability identified in TencentCloud Octop (through version 1.0.2b6) is categorized as a missing authorization vulnerability.\nThis flaw resides within the API implementation, specifically affecting endpoints used for provider management.\nAuthenticated, low-privileged users can exploit this vulnerability to retrieve sensitive plaintext API keys belonging to upstream LLM and voice service providers.\nThe lack of granular access control allows any user possessing a valid JWT to bypass intended security boundaries.\nThe risk implication is significant, as the exposure of these credentials permits unauthorized third parties to hijack upstream provider accounts, leading to potential financial exploitation, data leakage, and service abuse.\nSuccessful exploitation requires minimal effort, necessitating only an authenticated session and targeted requests to specific API endpoints.",
  "technicalDetails": "The root cause of this vulnerability is improper authorization enforcement within the TencentCloud Octop API framework. Specifically, the endpoints '/api/providers' and '/api/voice/providers' fail to perform adequate role-based access control (RBAC) or ownership validation checks against the requesting user's identity.\nWhile the application mandates that a request must present a valid JSON Web Token (JWT) to reach the controller logic, the backend fails to verify whether the authenticated user holds the necessary administrative privileges to view the sensitive configuration data managed by these endpoints.\nThe attack flow begins when an authenticated, low-privileged user constructs an HTTP GET request directed at the vulnerable endpoints. Because the backend logic focuses solely on the validity of the JWT signature rather than the claims or permission sets associated with the user, the application processes the request as authorized.\nUpon receiving the request, the application queries the underlying data store or configuration cache and returns a JSON response containing the plaintext API keys for various LLM and voice providers stored in the system.\nThe affected component is the API management module responsible for exposing provider settings. The vulnerability persists across all versions up to and including 1.0.2b6.\nExploitation is straightforward: once the plaintext credentials are exfiltrated, an attacker can programmatically interact with upstream service providers (such as OpenAI, Anthropic, or specialized voice synthesis platforms) using the hijacked API keys.\nThe post-exploitation impact includes, but is not limited to, the unauthorized consumption of paid service quotas, potential access to historical data logs stored within those third-party platforms, and the ability to perform malicious actions under the guise of the legitimate TencentCloud Octop instance's credentials.\nNetwork exposure is effectively equivalent to the reach of the API server itself; any network segment capable of communicating with the Octop API gateway allows a threat actor to execute this reconnaissance and exfiltration process."
}
CVE-2026-108581: TencentCloud Octop API Key Exposure (MEDIUM Severity, CVSS: 6.5) | Sceawere