OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 21:16
Updated : 2026-08-18 16:18
NVD link : CVE-2026-75480
Mitre link : CVE-2026-75480
CVE.ORG link : CVE-2026-75480
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
