VYPR

vearch

by Vearch

CVEs (1)

  • CVE-2026-108746HigOct 11, 2026
    risk 0.57cvss 8.8epss —

    Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only…