Missing Authorization Vulnerability in Odysseus Server Configuration
CVE-2026-70619

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
4 August 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-70619?

Odysseus prior to a specific commit is susceptible to a missing authorization vulnerability. This flaw enables authenticated non-admin users to manipulate server-wide embedding backend configurations by utilizing endpoint management routes that authenticate sessions but lack an admin authorization guard. By exploiting this vulnerability, attackers can submit a malicious URL to override the stored embedding backend settings, which may lead to sensitive data, such as chat messages and queries, being sent in plaintext to their controlled destinations. Additionally, attackers could delete the endpoint configuration, effectively denying embedding services to all legitimate users.

Affected Version(s)

odysseus 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Darkroom4364
Yunus AYDIN
.