Sceawere

Vulnerability Detail

CVE-2026-108853UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

UnicomAI Wanwu IDOR Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
UnicomAI
Product
Wanwu
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying their appId. Attackers can send requests to DELETE /v1/appspace/app with guessed sequential assistant IDs to permanently delete victims' applications, workflows, conversations, and associated data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-11T14:17:04.960Z",
  "pubdate": "2026-10-11T14:17:04.960Z",
  "executiveSummary": "UnicomAI Wanwu versions prior to 0.6.3 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. The flaw resides within the application's resource management logic, specifically affecting the handling of agent and RAG application deletion requests. Authenticated low-privileged users can exploit this vulnerability to bypass authorization checks and delete resources belonging to other tenants. By manipulating the 'appId' parameter in DELETE requests, an attacker can target arbitrary applications across the platform. The impact is critical, as successful exploitation results in the permanent loss of agent configurations, workflows, conversation history, and associated data. This vulnerability stems from a failure to perform server-side validation of ownership or authorization levels before executing administrative delete operations. The attack requires authenticated access to the platform but does not require higher administrative privileges, making it a significant risk to multi-tenant data integrity and service availability.",
  "technicalDetails": "The vulnerability exists in the endpoint /v1/appspace/app, which is responsible for the removal of agent and RAG application objects. The root cause of this IDOR is the lack of proper access control verification during the deletion workflow. When an authenticated user initiates a DELETE request to this endpoint, the system relies on the provided 'appId' to identify the target resource. However, the backend application fails to verify whether the requester possesses the required permissions or legitimate ownership of the resource associated with the supplied ID.\nThe exploitation process follows a predictable pattern due to the use of sequential identifiers for assistants and applications. An attacker can perform reconnaissance to determine the format of the 'appId'. Because the system generates these IDs in a predictable, sequential manner, an attacker can iterate through a range of integer values to discover valid application IDs belonging to other tenants. Once an ID is identified, the attacker crafts a malicious HTTP DELETE request targeting /v1/appspace/app with the harvested 'appId'.\nUpon receiving the request, the server executes the deletion logic without confirming if the authenticated session identity corresponds to an owner or an authorized administrator of the target resource. This results in an unauthorized state-changing operation. The post-exploitation impact is severe, as the deletion is permanent and triggers a cascading removal of all related system objects, including workflows, RAG knowledge bases, and conversation archives linked to the deleted application. This flaw essentially allows a malicious actor to perform a cross-tenant data destruction attack by leveraging the platform's internal API functions. The vulnerability persists across all deployments of UnicomAI Wanwu prior to version 0.6.3 and highlights a critical failure in the implementation of the principle of least privilege within the authorization layer."
}
CVE-2026-108853: UnicomAI Wanwu IDOR Vulnerability (HIGH Severity, CVSS: 8.1) | Sceawere