OpenObserve Cloud-Native Observability Platform Vulnerability
CVE-2026-63645

7.5HIGH

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-63645?

OpenObserve, a cloud-native observability platform, previously registered the /config/runtime endpoint without proper authentication. This security oversight allowed unauthenticated network clients to access serialized server configurations that included sensitive information. Despite the implementation of the hide_sensitive_fields keyword filter, it failed to obscure specific fields such as dsn and creds, enabling attackers to retrieve database credentials, internal communication addresses, and valuable system details in plaintext. This significant vulnerability has been addressed in version 0.90.3, which reinforces security measures to prevent unauthorized access.

Affected Version(s)

openobserve < 0.90.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.