216.73.217.22

CVE-2026-40252

· Published 10/04/2026 21:16 · Modified 10/04/2026 21:16

Labels: CVE-2026-40252 2026-04-10CVE-2026-40252CWE-284[email protected]

Essential information

Published
10/04/2026 21:16
Modified
10/04/2026 21:16
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams by supplying a foreign appId. While the API correctly validates the team token, it does not verify that the requested application belongs to the authenticated team. This leads to cross-tenant data exposure and unauthorized execution of private AI workflows. This vulnerability is fixed in 4.14.10.4.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fastgpt / fastgpt cpe:2.3:a:fastgpt:fastgpt:<4.14.10.4:*:*:*:*:*:*:*

References