PatchSiren cyber security CVE debrief
CVE-2026-65318 Weaviate CVE debrief
CVE-2026-65318 is a critical unauthenticated server-side request forgery vulnerability in Verba RAG application version 2.1.3. The vulnerability allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. This could lead to the retrieval of sensitive credentials from co-located database endpoints or cloud instance metadata services. Security teams and administrators should prioritize patching this vulnerability to prevent potential exploitation, focusing on affected product deployments and reviewing official advisories for validation.
- Vendor
- Weaviate
- Product
- Verba
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Security teams and administrators of Verba RAG application version 2.1.3 should prioritize patching this vulnerability to prevent potential exploitation. Additionally, vulnerability management teams, platform administrators, and security teams responsible for monitoring and incident response should be aware of the potential impact and take necessary precautions to protect their environments.
Technical summary
The vulnerability exists in the WebSocket import endpoint of Verba RAG application version 2.1.3. An unauthenticated attacker can connect to the /ws/import_files WebSocket endpoint, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources. This could result in the exposure of sensitive information, such as credentials, from internal systems. The vulnerability has a critical CVSS score of 9.2, indicating a high severity level.
Defensive priority
High priority should be given to patching this vulnerability due to its critical CVSS score of 9.2 and the potential for unauthenticated exploitation.
Recommended defensive actions
- Apply the latest patch or update for Verba RAG application version 2.1.3
- Restrict access to the /ws/import_files WebSocket endpoint
- Monitor for suspicious activity on the WebSocket import endpoint
- Implement additional security measures such as Web Application Firewalls (WAFs) to detect and prevent exploitation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-21T22:19:10.490Z and has not been modified since then. The NVD entry is currently being reviewed for accuracy and completeness. Security teams should verify the affected product deployments in their managed environments and review the official advisory for validation of affected scope, severity, and vendor guidance. Evidence limits suggest that defenders should focus on verifying the vulnerability in their specific environments.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:10.490Z and has not been modified since then.