CVE-2026-108550
Last modified
CVE-2026-108550 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens, roles and namespace ownership..
Description
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens, roles and namespace ownership.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| iflytek | skillhub | < 0.2.22 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-108550?
How severe is CVE-2026-108550?
How do I fix CVE-2026-108550?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-108545SillyTavern 1.12.13 through 1.19.0 contains a denial of serv…5.9
- CVE-2026-108546Spotweb through 1.5.8 contains an OS command injection vulne…7.5
- CVE-2026-108547AstronRPA through 1.1.6 contains a missing tenant authorizat…6.5
- CVE-2026-108548AstronRPA through 1.1.6 contains an authentication bypass vu…7.3
- CVE-2026-108549cc-connect through 1.5.0 contains a missing authentication v…8.1
- CVE-2026-10855An authorization flaw existed in the MISP Event Template Imp…4.3
- CVE-2026-108551openapi-typescript-codegen through 0.31.0 contains a code in…9.8
- CVE-2026-108553OpenRefine through 3.10.1 contains a cross-site request forg…7.5
- CVE-2026-108554PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-s…5.3
- CVE-2026-108555PairDrop through 1.11.2 contains an IP spoofing vulnerabilit…4.2
- CVE-2026-10856A URL validation flaw in the MISP dashboard button widget al…6.1
- CVE-2026-10857Improper neutralization of input during web page generation …6.1
Are you affected by CVE-2026-108550?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
