Impact
Shuffle through version 2.2.1 has a flaw in the HandleApiGeneration endpoint that lets a user with administrator rights reset and retrieve the API keys of other users who belong to separate organizations. By supplying arbitrary user identifiers to the endpoint, an attacker can generate valid keys for non‑admin accounts in other tenants, effectively bypassing tenant isolation and taking over those accounts. The vulnerability directly compromises the confidentiality and integrity of credentials without requiring any additional privileges beyond those of a local administrator.
Affected Systems
The affected product is Shuffle by Shuffle, version 2.2.1. No additional vendor or product variants are mentioned in the advisory. The flaw is present only in this specific release; newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1% shows that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack requires only administrator rights and an exposed API, an organization with many tenants could experience a cross‑tenant takeover if an admin role is compromised or misused.
OpenCVE Enrichment