PatchSiren

Weaviate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Weaviate CVE published 2026-07-21

CVE-2026-65318

CVE-2026-65318 is a critical unauthenticated server-side request forgery vulnerability in Verba RAG application version 2.1.3. The vulnerability allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. This could lead to the retrieval of sensitive credentials from co-located database endpoints or [truncated]

HIGH weaviate CVE published 2026-07-02

CVE-2026-59093

CVE-2026-59093 is a high-severity vulnerability in Weaviate, a cloud-native, modular, and open-source vector search engine. The vulnerability allows for role-assignment escalation, potentially leading to full administrative control of the database. Weaviate versions prior to 1.38.0 are affected. The vulnerability is caused by the assignRoleToUser and assignRoleToGroup handlers not verifying that a princip [truncated]

LOW weaviate CVE published 2026-06-08

CVE-2026-11500

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. It is stated that the exploi [truncated]