CVE-2026-75480: OpenViking Debug Vector Endpoints Multi-tenant Data Exposure
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-75480?
CVE-2026-75480 has a medium severity rating of 6.5.
What is CVE-2026-75480?
CVE-2026-75480 refers to a vulnerability in OpenViking debug vector endpoints that allows authenticated users to access co-tenant records due to insufficient user-level access controls.
How do I fix CVE-2026-75480?
To mitigate CVE-2026-75480, implement proper user-level access controls that restrict visibility to only user-specific data.
What are the potential impacts of CVE-2026-75480?
CVE-2026-75480 can lead to unauthorized access to sensitive information, including private memories and resources of other users.
Who is affected by CVE-2026-75480?
CVE-2026-75480 affects users of the OpenViking Debug Vector Endpoints who do not have proper data access controls in place.