THREATOPS
THREAT OPSThreat News › IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)

IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)

lowoss_secPublished 2026-08-14

<p>Posted by Bakabaka_9 on Aug 14</p>Hi,<br /> <br /> In IXP Manager (tested on v7), an authenticated user with at least<br /> AUTH_CUSTUSER privileges can update or delete arbitrary API key records by<br /> directly addressing their numeric api_keys.id.<br /> <br /> The update path mass-assigns request data into the ApiKey model, and the<br /> model permits the apiKey attribute itself to be mass-

Original source: https://seclists.org/oss-sec/2026/q3/495