Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-92716: Shuffle 2.2.1 admin can reset other org users' API keys

CVE-2026-92716 · published 23 days ago
Summary

In Shuffle version 2.2.1, an administrator can reset and view API keys belonging to users in separate organizations by sending any user ID to a specific endpoint. This could let a privileged user take over accounts outside their own company. Apply the latest security update from Shuffle and review admin permissions to limit this capability.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
shuffle shuffle <= 2.2.1
Original advisory text
Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation
Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate valid API keys for users in different organizations, enabling account takeover across tenant boundaries.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-92716 · MITRE
Track software like this
Free during beta