CVE-2026-40252
Severity CVSS v4.0:
MEDIUM
Type:
CWE-284
Improper Access Control
Publication date:
10/04/2026
Last modified:
21/04/2026
Description
FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams by supplying a foreign appId. While the API correctly validates the team token, it does not verify that the requested application belongs to the authenticated team. This leads to cross-tenant data exposure and unauthorized execution of private AI workflows. This vulnerability is fixed in 4.14.10.4.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* | 4.14.10.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



