Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate valid API keys for users in different organizations, enabling account takeover across tenant boundaries.
References
Configurations
No configuration.
History
17 Sep 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/geo-chen/oss/blob/main/shuffle.md - |
16 Sep 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 18:17
Updated : 2026-09-17 17:17
NVD link : CVE-2026-92716
Mitre link : CVE-2026-92716
CVE.ORG link : CVE-2026-92716
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
