Executive brief
Shuffle is a security automation platform used for workflow orchestration and team collaboration. An admin user in one organization can exploit a vulnerability to reset and steal API keys from users in other separate organizations, leading to account takeover across organizational boundaries. This breaks the fundamental isolation between customer tenants that is critical in a multi-tenant SaaS platform.
Technical details
The HandleApiGeneration endpoint in Shuffle through version 2.2.1 fails to properly validate tenant isolation, allowing cross-tenant API key generation. An authenticated administrator in one organization can supply arbitrary user IDs to generate valid API keys for any user in different organizations. The vulnerability requires admin privileges in the attacker's own organization but no additional authentication to the target tenant. An attacker can gain full account access to users in other organizations by obtaining and using their generated API keys, effectively achieving lateral movement and privilege escalation across tenant boundaries.
Affected products
- Shuffle Shuffle through 2.2.1
Timeline
- 2026-09-16: disclosed