PatchSiren

orneryd CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH orneryd CVE published 2026-10-11

CVE-2026-108710

CVE-2026-108710: NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. This vulnerability allows users with limited privileges to retrieve sensitive information, potentially leading to unauthorized data access. Defenders should assess exposure and prioritize rem [truncated]