Skip to content
Threat Feed
critical advisory

Cross-Tenant Privilege Escalation in Shuffle

Shuffle through version 2.2.1 is vulnerable to a cross-tenant privilege escalation flaw in the HandleApiGeneration endpoint that allows an authenticated administrator to reset and steal API keys from other tenants.

CVE search metadata

CVE search record: CVE-2026-92716. Severity: critical. CVSS: 9.6. KEV: no. Product: Shuffle through (2.2.1). Brief: Cross-Tenant Privilege Escalation in Shuffle. Brief link: https://feed.craftedsignal.io/briefs/2026-09-shuffle-privilege-escalation/

Shuffle through version 2.2.1 contains a severe security vulnerability (CVE-2026-92716) that facilitates cross-tenant privilege escalation. The vulnerability resides within the HandleApiGeneration endpoint. An attacker who has already obtained administrator privileges within one Shuffle tenant can leverage this endpoint to perform unauthorized actions against other organizations using the platform. Specifically, by supplying arbitrary user IDs to the vulnerable endpoint, an administrator can trigger a reset of API keys for users belonging to different organizations. The endpoint then returns the generated keys to the attacker, effectively granting them full programmatic access to the victim's account across tenant boundaries. This flaw represents a critical security risk for multi-tenant environments where the isolation of administrative control is expected.

Impact

The exploitation of this vulnerability allows for complete cross-tenant account takeover. An attacker can access sensitive data, modify workflow configurations, and perform unauthorized actions within the victim's organization, bypassing the intended logical isolation between tenants.

Recommendation

Prioritize the investigation of administrative account logs to identify any requests to the HandleApiGeneration endpoint referencing User IDs belonging to different organization identifiers. If available, restrict access to administrative API endpoints via network-level controls or WAF rules to known trusted administrative IP addresses. Immediately upgrade all Shuffle through instances to a patched version once released by the vendor to eliminate the underlying logic flaw.


Immediate actions

Audit logs for unauthorized access to the HandleApiGeneration endpoint.

SOC 24h

Mitigations

Monitor for and apply updates for Shuffle through as soon as they become available to remediate CVE-2026-92716.

immediate IT Operations

CVE-2026-92716