CVE-2026-108550 | iFlytek SkillHub up to 0.2.21 Merge Flow AccountMergeService/AccountMergeController improper authorization

SecurityVulns

A vulnerability marked as critical has been reported in iFlytek SkillHub up to 0.2.21. Affected is the function AccountMergeService/AccountMergeController of the component Merge Flow. Performing a manipulation results in improper authorization.

This vulnerability is reported as CVE-2026-108550. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More