PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75480 volcengine CVE debrief

CVE-2026-75480 is a high-severity vulnerability in OpenViking's debug vector scroll and count endpoints. The issue allows authenticated users to read all co-tenant records without user-level access controls, potentially exposing private memories, resources, skills, and secret material. This vulnerability has a CVSS score of 7.1 and is considered high severity.

Vendor
volcengine
Product
OpenViking
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-24
Advisory published
2026-08-17
Advisory updated
2026-09-24

Who should care

Defenders and administrators of OpenViking instances, especially in multi-tenant environments, should assess exposure and prioritize mitigation. They should verify the affected versions and configurations, review vendor guidance, and assess potential exposure. This includes reviewing compensating controls for exposed systems, checking relevant monitoring, detection, and logs for exposed assets, and tracking exceptions and retesting remediated assets.

Why it matters

CVE-2026-75480 is a high-severity vulnerability in OpenViking that allows authenticated users to read all co-tenant records. Defenders should prioritize verifying and mitigating this vulnerability, especially in multi-tenant environments.

  • Potential exposure of private memories, resources, skills, and secret material
  • Authenticated users can read all co-tenant records without administrative privileges
  • Verification of affected versions and remediation efforts are required

Technical summary

The OpenViking debug vector scroll and count endpoints do not apply user-level access controls, allowing authenticated users to read all co-tenant records. This vulnerability has a CVSS score of 7.1 and is considered high severity. The issue arises from the endpoints' account-level scoping without user-level access controls, potentially exposing private memories, resources, skills, and secret material. Defenders should prioritize verifying and mitigating this vulnerability, especially in multi-tenant environments. The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources is limited.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially in multi-tenant environments.

Recommended defensive actions

  • Verify and apply patches or mitigations provided by the vendor
  • Restrict access to the affected endpoints
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources is limited. Defenders should verify the affected versions and configurations, review vendor guidance, and assess potential exposure. The OpenViking debug vector scroll and count endpoints' lack of user-level access controls allows authenticated users to read all co-tenant records, potentially exposing private memories, resources, skills, and secret material. Evidence from the CVE Program and NVD suggests a

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75480 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75480

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75480 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75480

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.