Vulnerability  ·  2026-10-12

UnicomAI Wanwu: authorization bypass mints AppKeys bound to other users' MCP servers (CVSS 4.2)

VulnerabilityMedium impactGlobalCVE-2026-108856
VulnCheck published CVE-2026-108856 (published 2026-10-11, CVSS 4.2, CWE-639) for UnicomAI Wanwu ≤ 0.6.5: AppKey minting does not verify ownership of the target MCP server, so keys can be bound to other users' servers and used to invoke their tools. Verified against NVD REST API.
A cross-user MCP-key authorization bug: an attacker can impersonate another user's MCP server authentication, invoking agent tools that are meant to be scoped to the owning tenant. Low CVSS and the need to know a server UUID keep this at precision-tier C.
An authenticated user supplies a victim's MCP server UUID with appType mcpserver to POST /v1/appspace/app/key (CWE-639), minting an AppKey that opens MCP sessions and invokes the victim's server tools using their upstream auth.
UnicomAI Wanwu through 0.6.5
Upgrade past 0.6.5 (fix in later Wanwu releases); audit minted AppKeys for unexpected MCP server bindings. Advisory: https://www.vulncheck.com/advisories/unicomai-wanwu-through-0.6.5-authorization-bypass-via-v1-appspace-app-key-appkey-minting
NVD CVE-2026-108856VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →