CVE-2026-4400
MEDIUMMultiple vulnerabilities in 1millionbot Millie chatbot
Title source: cnaDescription
Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation ID. The vulnerability is present in the endpoint 'api.1millionbot.com/api/public/conversations/' and, if exploited, could allow a remote attacker to access other users private chatbot conversations, revealing sensitive or confidential data without requiring credentials or impersonating users. In order for the vulnerability to be exploited, the attacker must have the user's conversation ID.
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
16.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (3)
1millionbot/Millie chat
3.6.0
1millionbot/millie_chat_bot
< 3.6.0
1millionbot/millie_chatbot
< 3.6.0
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026