Multi-Tenant Data Exposure in OpenViking by Volcengine
CVE-2026-75480

7.1HIGH

Key Information:

Vendor

Volcengine

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75480?

The OpenViking platform has a vulnerability that allows authenticated users to access sensitive data belonging to other users within the same account. This flaw arises from the implementation of account-level scoping without sufficient user-level access controls. As a result, attackers can exploit certain debug vector scroll and count endpoints to retrieve private information, including resources and skills, compromising user privacy without the need for administrative privileges.

Affected Version(s)

OpenViking 0 <= 0.4.14

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.