CVE-2026-81027 | songquanpeng one-api up to 0.6.10 Channel Pinning middleware/auth.go model.IsAdmin channelid improper authorization

SecurityVulns

A vulnerability was found in songquanpeng one-api up to 0.6.10 and classified as critical. This vulnerability affects the function model.IsAdmin of the file middleware/auth.go of the component Channel Pinning. Such manipulation of the argument channelid leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-81027. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More