PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105145 Weaviate CVE debrief

A vulnerability was found in Weaviate Verba up to 2.1.3, affecting the get_environment function in goldenverba/components/util.py. This issue leads to information disclosure and can be exploited remotely. The exploit has been publicly disclosed, and although the vendor was notified, no response was received. Defenders should assess potential exposure and prioritize verification and monitoring of Weaviate Verba installations, especially those using version 2.1.3 or earlier. The vulnerability's impact on operational security and the lack of vendor response necessitate immediate attention.

Vendor
Weaviate
Product
Verba
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for Weaviate Verba installations, especially those using version 2.1.3 or earlier, should assess potential exposure and prioritize verification and monitoring.

Why it matters

Defenders should prioritize verifying exposure of Weaviate Verba installations, especially those using version 2.1.3 or earlier, and assess the potential for information disclosure due to the publicly disclosed exploit and unknown vendor response.

  • Potential information disclosure requires verification
  • Remote exploitation is possible
  • Vendor response and remediation status are unknown

Technical summary

The vulnerability affects the get_environment function in goldenverba/components/util.py of Weaviate Verba up to 2.1.3, leading to information disclosure. The CVSS score is 5.5, and the vulnerability can be exploited remotely. The exploit has been publicly disclosed, and although the vendor was notified, no response was received. Defenders should prioritize verifying exposure of Weaviate Verba installations, especially those using version 2.1.3 or earlier, and assess the potential for information disclosure due to the publicly disclosed exploit and unknown vendor response.

Defensive priority

Defenders should prioritize verifying exposure of Weaviate Verba installations, especially those using version 2.1.3 or earlier, and assess the potential for information disclosure.

Recommended defensive actions

  • Verify Weaviate Verba installations for version 2.1.3 or earlier
  • Assess potential exposure to information disclosure
  • Monitor for publicly disclosed exploits
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected components. However, the vendor's response and potential exploitation remain unknown.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105145 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105145

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105145 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105145

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.