CVE-2026-4400Disclosure(1millionbot / millie_chatbot)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation ID. The vulnerability is present in the endpoint 'api.1millionbot.com/api/public/conversations/' and, if exploited, could allow a remote attacker to access other users private chatbot conversations, revealing sensitive or confidential data without requiring credentials or impersonating users. In order for the vulnerability to be exploited, the attacker must have the user's conversation ID.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • millie_chatbot

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
millie_chatbot

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-31: 2Technical Details · 2026-03-31: 103-31
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Múltiples vulnerabilidades en Millie chat de #1millionbot #CVE CVE-2026-4399 y CVE-2026-4400 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-millie-chat-de-1millionbot #AvisosDeSeguridad #TI #CNA #0day

    Post summary

    An early warning from INCIBE lists CVE‑2026‑4399 and CVE‑2026‑4400 affecting Millie chat in 1millionbot, with no additional technical or exploitation information provided.

    03020382
    42.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4400 Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the co… https://www.cve.org/CVERecord?id=CVE-2026-4400

    Post summary

    The snippet announces CVE-2026-4400 as an IDOR flaw in 1millionbot Millie chat, enabling unauthorized viewing of private chats by altering a request parameter.

    00000114
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App1millionbotmillie_chatbot---

Explore more