CVE 7 HIGH

Multiple vulnerabilities in 1millionbot Millie chatbot_CVE-2026-4400

7 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

Description

Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation ID. The vulnerability is present in the endpoint 'api.1millionbot.com/api/public/conversations/' and, if exploited, could allow a remote attacker to access other users private chatbot conversations, revealing sensitive or confidential data without requiring credentials or impersonating users. In order for the vulnerability to be exploited, the attacker must have the user's conversation ID.

Basic Information

ID CVE-2026-4400
Source INCIBE
Published Mar 31, 2026 at 10:12
Modified Mar 31, 2026 at 13:30

Affected Product

Vendor 1millionbot
Product Millie chat
Version 3.6.0
Affected Versions 1millionbot Millie chat 3.6.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.