Sceawere

Vulnerability Detail

CVE-2026-108862UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

APIPark IDOR Credential Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
APIParkLab
Product
APIPark
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-11T14:17:06.220Z",
  "pubdate": "2026-10-11T14:17:06.220Z",
  "executiveSummary": "APIPark versions up to and including 1.9.7-beta are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability.\nThis flaw enables authenticated users to bypass access control mechanisms and retrieve sensitive plaintext API keys belonging to other applications.\nThe vulnerability exists within the application's authorization management module, specifically affecting the API endpoints responsible for fetching authorization metadata.\nThe risk implication is severe, as it facilitates unauthorized access to third-party services and infrastructure by compromising authentication credentials.\nExploitation requires the attacker to possess a valid account with 'authorization-view' permissions on at least one application within the platform.\nBy manipulating the request parameters to target foreign authorization UUIDs, an attacker can exfiltrate credentials regardless of the intended 'HideCredential' security configuration.\nThis vulnerability highlights a critical failure in server-side authorization enforcement, allowing horizontal privilege escalation across tenant boundaries.",
  "technicalDetails": "The vulnerability is rooted in an improper authorization check during the processing of requests directed at the /api/v1/app/authorization endpoint and its associated detail routes.\nThe system fails to validate that the requested authorization UUID belongs to an application owned by or accessible to the requesting user session.\nWhen an authenticated user with 'authorization-view' permissions submits a request to the application, the backend logic retrieves the requested object based solely on the provided UUID without verifying the relationship between the authenticated user's scope and the target object.\nThe exploitation process begins with the attacker identifying a valid authorization UUID for a target application, which can often be discovered through iterative enumeration or other information disclosure channels.\nThe attacker sends a GET request to /api/v1/app/authorization/{target_uuid}. The server processes this request and, due to the lack of restrictive object-level access controls, returns the complete object, including plaintext API keys.\nThis exposure persists even when the application administrator has explicitly enabled the 'HideCredential' configuration flag, as the vulnerable backend routine retrieves the credential fields directly from the database or data provider before any masking or filtering is applied.\nThe vulnerable component is the authorization retrieval controller, which trusts user-supplied UUIDs as a primary key without performing a second-order check against the application's RBAC (Role-Based Access Control) matrix.\nAffected versions include all releases up to and including 1.9.7-beta.\nThe impact is significant, providing attackers with the ability to perform full account takeover of downstream services integrated through the affected application's API keys.\nBecause the server responds with sensitive material in plain text, the breach is absolute, and no further brute-forcing or decryption is required by the attacker once the target UUID is obtained.\nThis represents a systemic failure in enforcing multi-tenancy isolation within the API layer, effectively nullifying the protection expected from the 'HideCredential' attribute."
}
CVE-2026-108862: APIPark IDOR Credential Disclosure (MEDIUM Severity, CVSS: 5.3) | Sceawere