Missing Authorization Vulnerability in Odysseus Server Configuration
CVE-2026-70619
What is CVE-2026-70619?
Odysseus prior to a specific commit is susceptible to a missing authorization vulnerability. This flaw enables authenticated non-admin users to manipulate server-wide embedding backend configurations by utilizing endpoint management routes that authenticate sessions but lack an admin authorization guard. By exploiting this vulnerability, attackers can submit a malicious URL to override the stored embedding backend settings, which may lead to sensitive data, such as chat messages and queries, being sent in plaintext to their controlled destinations. Additionally, attackers could delete the endpoint configuration, effectively denying embedding services to all legitimate users.
Affected Version(s)
odysseus 0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
