PatchSiren cyber security CVE debrief
CVE-2026-75480 volcengine CVE debrief
CVE-2026-75480 is a high-severity vulnerability in OpenViking's debug vector scroll and count endpoints. The issue allows authenticated users to read all co-tenant records without user-level access controls, potentially exposing private memories, resources, skills, and secret material. This vulnerability has a CVSS score of 7.1 and is considered high severity.
- Vendor
- volcengine
- Product
- OpenViking
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-24
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-24
Who should care
Defenders and administrators of OpenViking instances, especially in multi-tenant environments, should assess exposure and prioritize mitigation. They should verify the affected versions and configurations, review vendor guidance, and assess potential exposure. This includes reviewing compensating controls for exposed systems, checking relevant monitoring, detection, and logs for exposed assets, and tracking exceptions and retesting remediated assets.
Why it matters
CVE-2026-75480 is a high-severity vulnerability in OpenViking that allows authenticated users to read all co-tenant records. Defenders should prioritize verifying and mitigating this vulnerability, especially in multi-tenant environments.
- Potential exposure of private memories, resources, skills, and secret material
- Authenticated users can read all co-tenant records without administrative privileges
- Verification of affected versions and remediation efforts are required
Technical summary
The OpenViking debug vector scroll and count endpoints do not apply user-level access controls, allowing authenticated users to read all co-tenant records. This vulnerability has a CVSS score of 7.1 and is considered high severity. The issue arises from the endpoints' account-level scoping without user-level access controls, potentially exposing private memories, resources, skills, and secret material. Defenders should prioritize verifying and mitigating this vulnerability, especially in multi-tenant environments. The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources is limited.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially in multi-tenant environments.
Recommended defensive actions
- Verify and apply patches or mitigations provided by the vendor
- Restrict access to the affected endpoints
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but additional information from the vendor and other sources is limited. Defenders should verify the affected versions and configurations, review vendor guidance, and assess potential exposure. The OpenViking debug vector scroll and count endpoints' lack of user-level access controls allows authenticated users to read all co-tenant records, potentially exposing private memories, resources, skills, and secret material. Evidence from the CVE Program and NVD suggests a
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75480 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75480
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75480 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75480
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/volcengine/OpenViking
-
Source reference
Unverified legacy reference
URL: https://github.com/volcengine/OpenViking/blob/main/openviking/storage/viking_vector_index_backend.py
-
Source reference
Unverified legacy reference
URL: https://github.com/volcengine/OpenViking/issues/3724
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openviking-debug-vector-endpoints-multi-tenant-data-exposure
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.