High severity8.8NVD Advisory· Published Oct 11, 2026
CVE-2026-108746
CVE-2026-108746
Description
Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/entity/user.gonvd
- github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/master/services/role_service.gonvd
- hackmd.io/@haind/vearch-rbac-privilege-level-ignored-authz-bypassnvd
- www.vulncheck.com/advisories/vearch-3.5.2-through-3.5.9-incorrect-authorization-via-role-haspermissionforresourcesnvd
News mentions
0No linked articles in our index yet.