MEDIUM
APIParkLab
CVE published 2026-10-11
CVE-2026-108862
APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability allowing authenticated users to read other applications' credentials by supplying a foreign authorization UUID. This vulnerability, present in application authorization endpoints, enables users with authorization-view permissions to access plaintext API keys. Defenders should verify APIPark versions, restrict authorizati [truncated]