Description
Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass Leading to Unintended Data Disclosure
Action: Apply Patch
AI Analysis

Impact

Wukong AICRM up to the 20260610 release contains a missing authorization check that lets any logged‑in user send messages to chat sessions belonging to other users. By providing an arbitrary session identifier in the POST /chat/send request, an attacker can append messages and receive assistant replies generated from the target’s recent conversation history. The flaw effectively grants the attacker read access to the victim’s chat content and the ability to modify that content, exposing sensitive dialogue and potentially corrupting the chat data. The weakness is classified as CWE‑639, an authorization bypass.

Affected Systems

The vulnerability exists in the WuKongOpenSource Wukong AICRM product, specifically in versions released through and including 20260610. No other vendors or versions are currently listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, reflecting that the flaw requires the attacker to be an authenticated user with access to the application. Exploitation does not rely on elevated privileges beyond normal user rights and does not need network isolation, meaning any legitimate user within the system can abuse the flaw. The EPSS score is unavailable, and the vulnerability is not catalogued in CISA’s KEV list, but the straightforward nature of the exploit and its potential for privacy disclosure give it practical risk in environments where sensitive conversations occur.

Generated by OpenCVE AI on October 11, 2026 at 03:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Wukong AICRM to a version that removes the ability to pass an arbitrary sessionId to POST /chat/send.
  • If a patch cannot be applied immediately, add a server‑side check that ensures the sessionId in the request matches the authenticated user’s own session, rejecting all mismatches.
  • Configure application logs to alert on repeated attempts to write to sessions that are not owned by the requesting user and investigate any such activity.

Generated by OpenCVE AI on October 11, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content.
Title Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST /chat/send
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T01:12:24.286Z

Reserved: 2026-10-10T23:06:26.215Z

Link: CVE-2026-108689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T02:16:36.887

Modified: 2026-10-11T02:16:36.887

Link: CVE-2026-108689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T03:15:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key