CVE-2026-92716

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate valid API keys for users in different organizations, enabling account takeover across tenant boundaries.
Configurations

No configuration.

History

17 Sep 2026, 17:17

Type Values Removed Values Added
References () https://github.com/geo-chen/oss/blob/main/shuffle.md - () https://github.com/geo-chen/oss/blob/main/shuffle.md -

16 Sep 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 18:17

Updated : 2026-09-17 17:17


NVD link : CVE-2026-92716

Mitre link : CVE-2026-92716

CVE.ORG link : CVE-2026-92716


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key