CVE-2026-22680

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.
Configurations

Configuration 1 (hide)

cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-07 18:16

Updated : 2026-07-14 16:16


NVD link : CVE-2026-22680

Mitre link : CVE-2026-22680

CVE.ORG link : CVE-2026-22680


JSON object : View

Products Affected

volcengine

  • openviking
CWE
CWE-862

Missing Authorization