Sceawere
Vulnerability Detail
CVE-2026-108862UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
APIPark IDOR Credential Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- APIParkLab
- Product
- APIPark
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-11T14:17:06.220Z",
"pubdate": "2026-10-11T14:17:06.220Z",
"executiveSummary": "APIPark versions up to and including 1.9.7-beta are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability.\nThis flaw enables authenticated users to bypass access control mechanisms and retrieve sensitive plaintext API keys belonging to other applications.\nThe vulnerability exists within the application's authorization management module, specifically affecting the API endpoints responsible for fetching authorization metadata.\nThe risk implication is severe, as it facilitates unauthorized access to third-party services and infrastructure by compromising authentication credentials.\nExploitation requires the attacker to possess a valid account with 'authorization-view' permissions on at least one application within the platform.\nBy manipulating the request parameters to target foreign authorization UUIDs, an attacker can exfiltrate credentials regardless of the intended 'HideCredential' security configuration.\nThis vulnerability highlights a critical failure in server-side authorization enforcement, allowing horizontal privilege escalation across tenant boundaries.",
"technicalDetails": "The vulnerability is rooted in an improper authorization check during the processing of requests directed at the /api/v1/app/authorization endpoint and its associated detail routes.\nThe system fails to validate that the requested authorization UUID belongs to an application owned by or accessible to the requesting user session.\nWhen an authenticated user with 'authorization-view' permissions submits a request to the application, the backend logic retrieves the requested object based solely on the provided UUID without verifying the relationship between the authenticated user's scope and the target object.\nThe exploitation process begins with the attacker identifying a valid authorization UUID for a target application, which can often be discovered through iterative enumeration or other information disclosure channels.\nThe attacker sends a GET request to /api/v1/app/authorization/{target_uuid}. The server processes this request and, due to the lack of restrictive object-level access controls, returns the complete object, including plaintext API keys.\nThis exposure persists even when the application administrator has explicitly enabled the 'HideCredential' configuration flag, as the vulnerable backend routine retrieves the credential fields directly from the database or data provider before any masking or filtering is applied.\nThe vulnerable component is the authorization retrieval controller, which trusts user-supplied UUIDs as a primary key without performing a second-order check against the application's RBAC (Role-Based Access Control) matrix.\nAffected versions include all releases up to and including 1.9.7-beta.\nThe impact is significant, providing attackers with the ability to perform full account takeover of downstream services integrated through the affected application's API keys.\nBecause the server responds with sensitive material in plain text, the breach is absolute, and no further brute-forcing or decryption is required by the attacker once the target UUID is obtained.\nThis represents a systemic failure in enforcing multi-tenancy isolation within the API layer, effectively nullifying the protection expected from the 'HideCredential' attribute."
}