CVE-2026-75480

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 21:16

Updated : 2026-08-18 16:18


NVD link : CVE-2026-75480

Mitre link : CVE-2026-75480

CVE.ORG link : CVE-2026-75480


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization