Skip to content
Threat Feed
high advisory

UnicomAI Wanwu IDOR Vulnerability

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability (CVE-2026-108853) that allows authenticated attackers to delete unauthorized tenants' applications.

CVE search metadata

CVE search record: CVE-2026-108853. Severity: high. CVSS: 8.1. KEV: no. Product: Wanwu (< 0.6.3). Brief: UnicomAI Wanwu IDOR Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-unicomai-wanwu-idor/

UnicomAI Wanwu versions prior to 0.6.3 contain an insecure direct object reference (IDOR) vulnerability, tracked as CVE-2026-108853. This vulnerability enables an authenticated user with low privileges to delete agent or RAG applications belonging to other tenants. By manipulating the 'appId' parameter within specific API requests, an attacker can target other users' infrastructure. The vulnerability resides in the application's authorization logic, which fails to validate whether the requesting user has the appropriate permissions to perform delete operations on resources belonging to different tenant accounts. This flaw poses a significant risk to data integrity and platform availability, as it can be used to permanently erase workflows, conversation histories, and agent configurations across the multi-tenant environment.

Impact

Successful exploitation results in the permanent deletion of victims' applications, associated workflows, and conversation data. As the vulnerability allows for sequential ID guessing, an attacker could programmatically iterate through target IDs to cause large-scale data destruction within the platform, affecting potentially all tenants on a vulnerable instance.

Recommendation

  • Upgrade UnicomAI Wanwu to version 0.6.3 or later immediately to resolve the flawed authorization logic in the /v1/appspace/app endpoint.
  • Audit web server logs for high-frequency or anomalous DELETE requests to the /v1/appspace/app endpoint originating from low-privileged accounts.
  • Implement strict request rate limiting and monitoring for administrative or destructive API actions to detect and mitigate potential mass-deletion attempts.

Immediate actions

Upgrade UnicomAI Wanwu to 0.6.3 or later

IT Operations 48h

Mitigations

Upgrade to version 0.6.3 or later

immediate IT Operations

CVE-2026-108853