Vulnerability
Published 2026-10-11
Verified 2026-10-12

VulnCheck batch (11 Oct, later set): BotSharp AI agent framework ships a public JWT signing key that lets anyone act as admin (CVSS 9.3), Unla MCP gateway issues OAuth tokens without a login (8.8), Plano LLM proxy leaks provider API keys from an open Envoy admin port (8.7); pH7Builder dating CMS flaws fixed in 19.3.0

VulnCheck, acting as CVE numbering authority, published a further set of records late on 11 October 2026 (CVE-2026-108839 and CVE-2026-108850 to CVE-2026-108865, all credited to researcher hieuPenguinnn), nearly all in self-hosted AI agent, model-serving and Model Context Protocol (MCP) software. The most serious is CVE-2026-108860 in SciSharp BotSharp, the open-source .NET AI agent framework, through 5.2.0: the WebStarter appsettings.json commits a fixed Jwt:Key, so an unauthenticated attacker can sign bearer tokens with that secret and the fixed 'botsharp' issuer and audience and act as any known user, administrators included, on protected API routes (CVSS 4.0 9.3; 3.1 9.1). In AmoyLab Unla, an MCP gateway, through 0.10.0 (CVE-2026-108865, 8.8) the OAuth2 server never authenticates the resource owner, so anyone can register a client, get a code from /authorize and exchange it for a valid token that reaches OAuth-protected MCP prefixes, proxied upstream APIs and the credentials the gateway injects. Katanemo Plano, an Envoy-based proxy for LLM traffic, through 0.4.37 (CVE-2026-108863, 8.7) exposes the unauthenticated Envoy admin interface on all host interfaces on port 9901, and its /config_dump endpoint returns configured LLM provider API keys in plaintext. The mcp-go library through 1.2.1 reads whole POST bodies into memory before validating them, so unauthenticated clients can exhaust memory in StreamableHTTPServer (CVE-2026-108859, 8.7). In UnicomAI's Wanwu agent and RAG platform, CVE-2026-108853 (7.2) lets a low-privileged user delete other tenants' applications by guessing sequential ids; Wanwu 0.6.3 fixes it and the related AppKey deletion flaw CVE-2026-108854, but two more Wanwu bugs through 0.6.5 (CVE-2026-108855 and CVE-2026-108856) have no fix listed. Lower-rated records cover API keys or tokens written to logs by Hugging Face Text Embeddings Inference through 1.9.4 and Predibase LoRAX through 0.12.1, cross-application credential reads in the APIPark AI gateway through 1.9.7-beta, a field-level access-control bypass in the erpipe Odoo MCP server 1.0.0 to 1.3.2, restricted FAQ disclosure through the phpMyFAQ 4.1.x MCP search tool, SSRF in Company Research Agent through 2.2.0, cross-app workflow resume in iFlytek Astron Agent through 1.1.2, javascript: link XSS in the Deep Chat web component through 2.5.1 and a symlink file write in thClaws through 0.141.0. In the same tranche VulnCheck published four flaws in pH7Builder (pH7 Social Dating CMS) credited to Haluk Baran Akbulut of CyberMap Group; the worst, CVE-2026-108905 (8.7), lets unauthenticated attackers use a hard-coded private API key with a spoofed 'Host: localhost' header to pull member emails, IP addresses, phone numbers and bank account fields, and the set is fixed across 18.5.0, 18.6.0 and 19.3.0. Apart from Wanwu 0.6.3 and pH7Builder, the records list affected versions only. No exploitation has been reported. Primary: CVE records and VulnCheck advisories.

Product
BotSharp (SciSharp); Unla (AmoyLab); Plano (Katanemo); mcp-go (mark3labs); Wanwu (UnicomAI); Text Embeddings Inference (Hugging Face); LoRAX (Predibase); APIPark; Odoo MCP (erpipe); phpMyFAQ MCP server; Company Research Agent; Astron Agent (iFlytek); Deep Chat; thClaws; pH7Builder (pH7 Social Dating CMS)
Versions
BotSharp through 5.2.0; Unla through 0.10.0; Plano through 0.4.37; mcp-go through 1.2.1; Wanwu before 0.6.3 and through 0.6.5; Text Embeddings Inference through 1.9.4; LoRAX through 0.12.1; APIPark through 1.9.7-beta; Odoo MCP 1.0.0–1.3.2; phpMyFAQ 4.1.0–4.1.10; Company Research Agent through 2.2.0; Astron Agent through 1.1.2; Deep Chat 1.4.7–2.5.1; thClaws through 0.141.0; pH7Builder before 18.5.0 / 18.6.0 / 19.3.0
CVSS
Up to (CVSS 4.0) / 9.1 (CVSS 3.1) for BotSharp CVE-2026-108860; Unla 8.8; Plano, mcp-go and pH7Builder CVE-2026-108905 8.7; Wanwu CVE-2026-108853 7.2; others 2.1–6.9 (VulnCheck)
Exploited in Australia?
unknown
Patch to
pH7Builder: 19.3.0 or later (current 19.3.1). Wanwu: 0.6.3 fixes CVE-2026-108853/108854; no fix listed for 108855/108856. No fixed releases named for the others: in BotSharp replace the Jwt:Key in appsettings.json with your own long random secret (and rotate it); keep the Plano Envoy admin port (9901) and Unla OAuth endpoints off untrusted networks and rotate LLM provider keys they hold; cap request sizes in front of mcp-go servers; scrub and restrict access to Text Embeddings Inference and LoRAX router logs and telemetry.

Primary: CVE.org — CVE-2026-108860 BotSharp through 5.2.0 authentication bypass via hard-coded JWT signing key (VulnCheck CNA, published 11 Oct 2026) · Vendor: VulnCheck advisory — BotSharp through 5.2.0 authentication bypass via hard-coded JWT signing key · CVE: CVE-2026-108839, CVE-2026-108850, CVE-2026-108865, CVE-2026-108860, CVE-2026-108863, CVE-2026-108859, CVE-2026-108853, CVE-2026-108854, CVE-2026-108855, CVE-2026-108856, CVE-2026-108905 · VulnCheck advisory — AmoyLab Unla through 0.10.0 OAuth2 authentication bypass (CVE-2026-108865); wire: Tenable newest CVEs 11 Oct

tech ai