PatchSiren

UnicomAI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW UnicomAI CVE published 2026-10-11

CVE-2026-108856

CVE-2026-108856 is an authorization bypass vulnerability in UnicomAI Wanwu through version 0.6.5. The vulnerability allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers can supply a victim's MCP server UUID with appType mcpserver to open MCP sessions and invoke the server's tools using the victim's upstream authentication.

MEDIUM UnicomAI CVE published 2026-10-11

CVE-2026-108855

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T13:26:03.944Z and has not been modified since then. UnicomAI Wanwu through version 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. This could disrupt access and require ve [truncated]

MEDIUM UnicomAI CVE published 2026-10-11

CVE-2026-108854

CVE-2026-108854 is a medium-severity vulnerability in UnicomAI's Wanwu product, allowing authenticated users to delete other users' AppKeys via an insecure direct object reference (IDOR) vulnerability. This issue affects Wanwu versions before 0.6.3 and can lead to the revocation of AppKeys across organizations, breaking MCP and OpenAPI clients. The vulnerability is caused by inadequate access controls on [truncated]

HIGH UnicomAI CVE published 2026-10-11

CVE-2026-108853

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T13:26:02.706Z and has not been modified since then. UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying their appId. This could lead to data loss and s [truncated]