CVE-2026-108862
Description
APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/APIParkLab/APIPark
- https://github.com/APIParkLab/APIPark/blob/v1.9.7-beta/module/application-authorization/iml.go#L451-L511
- https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/apipark-cross-app-authorization-uuid
- https://www.vulncheck.com/advisories/apipark-through-1.9.7-beta-idor-via-application-authorization-endpoints
CWEs
CWE-639
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.