THREAT OPS › Threat News › IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)
IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)
<p>Posted by Bakabaka_9 on Aug 14</p>Hi,<br /> <br /> In IXP Manager (tested on v7), an authenticated user with at least<br /> AUTH_CUSTUSER privileges can update or delete arbitrary API key records by<br /> directly addressing their numeric api_keys.id.<br /> <br /> The update path mass-assigns request data into the ApiKey model, and the<br /> model permits the apiKey attribute itself to be mass-
Original source: https://seclists.org/oss-sec/2026/q3/495