CVE-2026-75480

Summary

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.

Affected Software

VendorProductVersion RangeStatus
volcengineOpenViking0 <= 0.4.14affected

Weaknesses

  • CWE-863: Incorrect Authorization

References