---
id: CVE-2026-92716
title: >-
  Shuffle through 2.2.1 contains a cross-tenant privilege escalation
  vulnerability in the HandleApiGeneration endpoint that allows administrators
  to reset and read API keys of non-administrator users in other organizations
summary: >-
  Shuffle through 2.2.1 contains a cross-tenant privilege escalation
  vulnerability in the HandleApiGeneration endpoint that allows administrators
  to reset and read API keys of non-administrator users in other organizations.
  Attackers with …
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-639
vendor: Shuffle
product: Shuffle
affected:
  - Shuffle <= 2.2.1
published: '2026-09-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:47:31.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92716'
references:
  - url: 'https://github.com/Shuffle/Shuffle'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Shuffle/shuffle-shared/blob/v1.2.50/shared.go#L9888-L9912
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Shuffle/shuffle-shared/commit/c1b582e91b429bc7d5ad02e6c22f98234ec67615
    label: disclosure@vulncheck.com
  - url: 'https://github.com/geo-chen/oss/blob/main/shuffle.md'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/shuffle-through-2.2.1-api-key-reset-cross-tenant-privilege-escalation
    label: disclosure@vulncheck.com
  - url: 'https://github.com/geo-chen/oss/blob/main/shuffle.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00426
epssPercentile: 0.34173
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-17T16:17:33.975791Z'
ingestedAt: '2026-09-16T18:01:17.461Z'
---

## Overview

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate valid API keys for users in different organizations, enabling account takeover across tenant boundaries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
