Vendor
UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability (CVE-2026-108853) that allows authenticated attackers to delete unauthorized tenants' applications.