Impact
The vulnerability resides in OpenViking’s debug vector scroll and count endpoints, which enforce only account-level scoping without enforcing user-level access controls. This omission allows any authenticated user to read records belonging to all other users within the same account, including private memories, resources, skills, and secret material. The weakness is classified as an authorization control failure (CWE-863).
Affected Systems
Affected product: OpenViking by volcengine. No specific version information is provided in the CNA data, so all releases of OpenViking are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity with a likelihood of exploitation moderate based on the need for authentication but not administrative rights. The EPSS score is not available, but the absence of a KEV listing does not reduce the risk, as the vulnerability could be exploited by any authenticated user with access to the debug endpoints. Attackers would exploit the endpoint by sending authenticated requests and could retrieve all co‑tenant data in the account.
OpenCVE Enrichment