Threat · curated 17 Jul 2026

Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

Coverage timeline

discovered wiz.io primary 17 Jul 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Base44's flaw shows that AI-powered app-building platforms can expose all private applications and data through a trivial parameter-based auth bypass, making them a high-value target for attackers seeking access to sensitive customer-built systems.

Wiz disclosed a now-patched critical authentication bypass in Base44, an AI-powered 'vibe coding' platform owned by Wix, where supplying only a non-secret 'app_id' value to undocumented registration and email-verification endpoints let an attacker create a verified account for private applications. The flaw bypassed all authentication controls, including SSO, granting full access to private apps and their data; Wix fixed it within 24 hours of the July 9, 2025 disclosure, with no evidence of exploitation in the wild.