PatchSiren

Vearch CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Vearch CVE published 2026-10-11

CVE-2026-108746

CVE-2026-108746 is an incorrect authorization vulnerability in Vearch 3.5.2 through 3.5.9, affecting the Role.HasPermissionForResources function. Authenticated non-root users can exploit this to upsert and delete documents or grant WriteRead privileges to their role, potentially escalating to cluster administrator access. The vulnerability allows unauthorized access and potential privilege escalation, imp [truncated]