Medium severity5.3NVD Advisory· Published Apr 1, 2026· Updated Apr 7, 2026
CVE-2026-34999
CVE-2026-34999
Description
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/volcengine/OpenViking/commit/27acda8d1701ff68423fbd6c902208e3c1ed9373nvdPatch
- www.vulncheck.com/advisories/openviking-bot-proxy-endpoints-allow-unauthenticated-accessnvdThird Party AdvisoryVDB Entry
- github.com/volcengine/OpenViking/pull/996nvdIssue Tracking
- github.com/volcengine/OpenViking/releases/tag/v0.2.14nvdRelease Notes
News mentions
0No linked articles in our index yet.