Medium severity6.5NVD Advisory· Published Aug 17, 2026
CVE-2026-75480
CVE-2026-75480
Description
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.