High severity8.1NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-7767
CVE-2024-7767
Description
An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:onyx:onyx:0.3.94:*:*:*:*:*:*:*
<=v0.3.94+ 1 more
- (no CPE)range: <=v0.3.94
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.