PatchSiren

APIParkLab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM APIParkLab CVE published 2026-10-11

CVE-2026-108862

APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability allowing authenticated users to read other applications' credentials by supplying a foreign authorization UUID. This vulnerability, present in application authorization endpoints, enables users with authorization-view permissions to access plaintext API keys. Defenders should verify APIPark versions, restrict authorizati [truncated]