Description
Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate valid API keys for users in different organizations, enabling account takeover across tenant boundaries.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑tenant privilege escalation enabling account takeover
Action: Immediate Patch
AI Analysis

Impact

Shuffle through version 2.2.1 has a flaw in the HandleApiGeneration endpoint that lets a user with administrator rights reset and retrieve the API keys of other users who belong to separate organizations. By supplying arbitrary user identifiers to the endpoint, an attacker can generate valid keys for non‑admin accounts in other tenants, effectively bypassing tenant isolation and taking over those accounts. The vulnerability directly compromises the confidentiality and integrity of credentials without requiring any additional privileges beyond those of a local administrator.

Affected Systems

The affected product is Shuffle by Shuffle, version 2.2.1. No additional vendor or product variants are mentioned in the advisory. The flaw is present only in this specific release; newer releases are not listed as affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1% shows that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack requires only administrator rights and an exposed API, an organization with many tenants could experience a cross‑tenant takeover if an admin role is compromised or misused.

Generated by OpenCVE AI on September 18, 2026 at 06:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Shuffle release that contains the fix for API key generation across tenants.
  • If an upgrade is not immediately possible, restrict the HandleApiGeneration endpoint to trusted administrators and disable external access for API key reset functions.
  • Implement multi‑factor authentication for all administrator accounts and audit admin actions for anomalous API key generation patterns.

Generated by OpenCVE AI on September 18, 2026 at 06:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Shuffle
Shuffle shuffle
Vendors & Products Shuffle
Shuffle shuffle

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate valid API keys for users in different organizations, enabling account takeover across tenant boundaries.
Title Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:50.529Z

Reserved: 2026-09-16T16:56:38.459Z

Link: CVE-2026-92716

cve-icon Vulnrichment

Updated: 2026-09-17T16:17:49.240Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T18:17:22.390

Modified: 2026-09-24T20:47:31.797

Link: CVE-2026-92716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key