<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:shuffle:shuffle_through:2.2.1:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ashuffleshuffle_through2.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 19:51:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ashuffleshuffle_through2.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Tenant Privilege Escalation in Shuffle</title><link>https://feed.craftedsignal.io/briefs/2026-09-shuffle-privilege-escalation/</link><pubDate>Wed, 16 Sep 2026 19:51:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-shuffle-privilege-escalation/</guid><description>Shuffle through version 2.2.1 is vulnerable to a cross-tenant privilege escalation flaw in the HandleApiGeneration endpoint that allows an authenticated administrator to reset and steal API keys from other tenants.</description><content:encoded><![CDATA[<p>Shuffle through version 2.2.1 contains a severe security vulnerability (CVE-2026-92716) that facilitates cross-tenant privilege escalation. The vulnerability resides within the HandleApiGeneration endpoint. An attacker who has already obtained administrator privileges within one Shuffle tenant can leverage this endpoint to perform unauthorized actions against other organizations using the platform. Specifically, by supplying arbitrary user IDs to the vulnerable endpoint, an administrator can trigger a reset of API keys for users belonging to different organizations. The endpoint then returns the generated keys to the attacker, effectively granting them full programmatic access to the victim's account across tenant boundaries. This flaw represents a critical security risk for multi-tenant environments where the isolation of administrative control is expected.</p>
<h2 id="impact">Impact</h2>
<p>The exploitation of this vulnerability allows for complete cross-tenant account takeover. An attacker can access sensitive data, modify workflow configurations, and perform unauthorized actions within the victim's organization, bypassing the intended logical isolation between tenants.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the investigation of administrative account logs to identify any requests to the HandleApiGeneration endpoint referencing User IDs belonging to different organization identifiers. If available, restrict access to administrative API endpoints via network-level controls or WAF rules to known trusted administrative IP addresses. Immediately upgrade all Shuffle through instances to a patched version once released by the vendor to eliminate the underlying logic flaw.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>