File Access Vulnerability in Onyx AI Platform by Onyx
CVE-2026-42277

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-42277?

The Onyx AI platform exposes a significant access control vulnerability where authenticated users can download files from other users by using the file's UUID. By exploiting this flaw, unauthorized users could potentially gain access to sensitive documents and chat attachments, putting confidential information at risk. The issue is resolved in versions 3.0.9, 3.1.6, and 3.2.6, where the necessary checks have been added to restrict access to files owned by the authenticated user.

Affected Version(s)

onyx < 3.0.9 < 3.0.9

onyx >= 3.1.0, < 3.1.6 < 3.1.0, 3.1.6

onyx >= 3.2.0, < 3.2.6 < 3.2.0, 3.2.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.