Description
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
Published: 2026-08-17
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in OpenViking’s debug vector scroll and count endpoints, which enforce only account-level scoping without enforcing user-level access controls. This omission allows any authenticated user to read records belonging to all other users within the same account, including private memories, resources, skills, and secret material. The weakness is classified as an authorization control failure (CWE-863).

Affected Systems

Affected product: OpenViking by volcengine. No specific version information is provided in the CNA data, so all releases of OpenViking are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity with a likelihood of exploitation moderate based on the need for authentication but not administrative rights. The EPSS score is not available, but the absence of a KEV listing does not reduce the risk, as the vulnerability could be exploited by any authenticated user with access to the debug endpoints. Attackers would exploit the endpoint by sending authenticated requests and could retrieve all co‑tenant data in the account.

Generated by OpenCVE AI on August 17, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update OpenViking to the latest version that enforces user‑level access control on debug endpoints.
  • If a patch is not immediately available, disable the debug vector scroll and count endpoints to prevent unauthorised data exposure.
  • Implement audit logging and monitor for repeated unauthorised queries to the debug endpoints to detect and respond to potential misuse.

Generated by OpenCVE AI on August 17, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
Title OpenViking Debug Vector Endpoints Multi-tenant Data Exposure
First Time appeared Volcengine
Volcengine openviking
Weaknesses CWE-863
CPEs cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*
Vendors & Products Volcengine
Volcengine openviking
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Volcengine Openviking
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-17T20:36:06.111Z

Reserved: 2026-08-17T19:59:23.460Z

Link: CVE-2026-75480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T21:16:50.477

Modified: 2026-08-17T21:16:50.477

Link: CVE-2026-75480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T21:30:03Z

Weaknesses