Vulnerability  ·  2026-10-12

UnicomAI Wanwu: cross-tenant IDOR lets low-priv users delete other tenants' agent/RAG applications (CVSS 8.1)

VulnerabilityHigh impactGlobalCVE-2026-108853
VulnCheck published CVE-2026-108853 (published 2026-10-11, CVSS 8.1, CWE-639) for UnicomAI Wanwu < 0.6.3: the appspace delete endpoint performs no ownership/tenant check, so low-privilege users can delete other tenants' applications by iterating sequential IDs. Verified against NVD REST API; fixed in v0.6.3.
Wanwu is an agent/RAG application platform; this breaks cross-tenant isolation with destructive consequences — an authenticated user can wipe another organization's AI agent applications, workflows and conversation data at scale, a high-impact availability and integrity breach for shared AI deployments.
Authenticated low-privileged user sends DELETE /v1/appspace/app with a guessed sequential appId (CWE-639 IDOR), permanently destroying other tenants' agent/RAG applications, workflows, conversations and associated data.
UnicomAI Wanwu before 0.6.3 (github.com/UnicomAI/wanwu)
Upgrade to Wanwu v0.6.3 or later (https://github.com/UnicomAI/wanwu/releases/tag/v0.6.3); review/rotate shared data stores if compromise suspected. Advisory: https://www.vulncheck.com/advisories/unicomai-wanwu-before-0.6.3-idor-via-delete-v1-appspace-app
NVD CVE-2026-108853VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →