<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:unicomai:wanwu:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aunicomaiwanwu/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 16:02:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aunicomaiwanwu/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>UnicomAI Wanwu IDOR Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-unicomai-wanwu-idor/</link><pubDate>Sun, 11 Oct 2026 16:02:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-unicomai-wanwu-idor/</guid><description>UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability (CVE-2026-108853) that allows authenticated attackers to delete unauthorized tenants' applications.</description><content:encoded><![CDATA[<p>UnicomAI Wanwu versions prior to 0.6.3 contain an insecure direct object reference (IDOR) vulnerability, tracked as CVE-2026-108853. This vulnerability enables an authenticated user with low privileges to delete agent or RAG applications belonging to other tenants. By manipulating the 'appId' parameter within specific API requests, an attacker can target other users' infrastructure. The vulnerability resides in the application's authorization logic, which fails to validate whether the requesting user has the appropriate permissions to perform delete operations on resources belonging to different tenant accounts. This flaw poses a significant risk to data integrity and platform availability, as it can be used to permanently erase workflows, conversation histories, and agent configurations across the multi-tenant environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the permanent deletion of victims' applications, associated workflows, and conversation data. As the vulnerability allows for sequential ID guessing, an attacker could programmatically iterate through target IDs to cause large-scale data destruction within the platform, affecting potentially all tenants on a vulnerable instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade UnicomAI Wanwu to version 0.6.3 or later immediately to resolve the flawed authorization logic in the /v1/appspace/app endpoint.</li>
<li>Audit web server logs for high-frequency or anomalous DELETE requests to the /v1/appspace/app endpoint originating from low-privileged accounts.</li>
<li>Implement strict request rate limiting and monitoring for administrative or destructive API actions to detect and mitigate potential mass-deletion attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>idor</category><category>impact</category></item></channel></rss>