CVE-2026-108689: Authorization Bypass Through User-Controlled Key in WuKongOpenSource Wukong AICRM
Description
CVE-2026-108689 is an authorization bypass vulnerability in Wukong AICRM version 0 that allows authenticated users to write into other users' AI chat sessions by specifying arbitrary session IDs. This enables attackers to append messages to victims' conversations and receive assistant replies based on the victim's recent messages, potentially disclosing sensitive conversation content.
CVSS v4.0
Score 5.3medium
Affected software
WuKongOpenSource
Wukong AICRM
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Wukong AICRM through version 0 contains a missing authorization vulnerability where authenticated users can supply arbitrary sessionId values to the POST /chat/send endpoint. This flaw allows attackers to append messages to other users' AI chat sessions and receive streamed assistant replies constructed from the victim's last 20 messages, thereby leaking conversation content. The vulnerability is identified as CVE-2026-108689 with a CVSS 4.0 base score of 5.3 (medium severity).
Potential Impact
An attacker with authenticated access can manipulate other users' AI chat sessions by injecting messages and receiving assistant responses based on the victim's conversation history, leading to unauthorized disclosure of sensitive chat content.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user permissions to prevent unauthorized session ID manipulation if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-10T23:06:26.215Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6acaeb242cdf04f656a49dba
Added to database: 10/11/2026, 01:49:24 UTC
Last enriched: 10/11/2026, 02:03:56 UTC
Last updated: 10/11/2026, 02:04:02 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.