Junglewise Threat Intelligence

CVE-2026-16953: Neuron AI Engine privilege escalation via unverified session cookie

CVE-2026-16953 · Severity: medium · CVSS 4.8 · Published 2026-08-08

Technologies: Neuron AI Engine.

Executive brief

The AI Engine WordPress plugin allows unauthenticated guests to upload chatbot files. However, the plugin fails to properly verify that a user actually owns a file before allowing deletion—it relies solely on a session cookie value that an attacker can forge or steal. An attacker who learns a victim's session ID and file ID can delete that victim's uploaded files without authorization, causing data loss.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the file deletion endpoint of the AI Engine WordPress plugin. The plugin's `/wp-json/mwai-ui/v1/files/delete` REST endpoint checks file ownership by comparing the provided session cookie (`mwai_session_id`) against stored ownership metadata, but accepts any cookie value supplied by the client without cryptographic validation or server-side session binding. An unauthenticated attacker can enumerate or obtain a victim's session ID and file reference ID through various means (network sniffing, OSINT, brute force), then forge a request with the victim's cookie to delete their files. The root cause is the absence of server-side session verification and the reliance on client-supplied cookies as a sole authorization mechanism. Exploitation requires network access to the WordPress site and knowledge of the target's session ID and file ID, but no user interaction or authentication. The plugin was patched in version 3.6.4.

Affected products

  • Neuron AI Engine before 3.6.4

Timeline

  • 2026-08-03: disclosed: Published on WPScan
  • 2026-08-03: patched: Fix released in version 3.6.4

References