PatchSiren cyber security CVE debrief
CVE-2026-11500 weaviate CVE debrief
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading to version 1.38.0-rc.0 is able to resolve this issue. The identifier of the patch is 40f2cc32279f0f8a51016c3c6870a2c0c808e6c0.
- Vendor
- weaviate
- Product
- weaviate
- CVSS
- LOW 1.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-08
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-06-08
- Advisory updated
- 2026-07-23
Who should care
Users of Weaviate up to version 1.37.7 should be aware of this vulnerability and take steps to upgrade to a patched version.
Technical summary
The vulnerability is caused by a flaw in the validateConfig function of the Static API Key Handler in Weaviate up to 1.37.7. This allows for authorization bypass, which can be exploited remotely with high complexity and difficult exploitability.
Defensive priority
LOW
Recommended defensive actions
- Upgrade to version 1.38.0-rc.0 or later to resolve this issue.
- Apply the patch with identifier 40f2cc32279f0f8a51016c3c6870a2c0c808e6c0.
Evidence notes
The CVE record and details were sourced from official vulnerability databases and vendor information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-11500 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-11500
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-11500 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11500
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/weaviate/weaviate/
-
Source reference
Unverified legacy reference
URL: https://github.com/weaviate/weaviate/commit/40f2cc32279f0f8a51016c3c6870a2c0c808e6c0
-
Source reference
Unverified legacy reference
URL: https://github.com/weaviate/weaviate/issues/11392
-
Source reference
Unverified legacy reference
URL: https://github.com/weaviate/weaviate/releases/tag/v1.38.0-rc.0
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-11500
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/835080
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/369120
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.