Multi-Tenant Data Exposure in OpenViking by Volcengine
CVE-2026-75480
7.1HIGH
What is CVE-2026-75480?
The OpenViking platform has a vulnerability that allows authenticated users to access sensitive data belonging to other users within the same account. This flaw arises from the implementation of account-level scoping without sufficient user-level access controls. As a result, attackers can exploit certain debug vector scroll and count endpoints to retrieve private information, including resources and skills, compromising user privacy without the need for administrative privileges.
Affected Version(s)
OpenViking 0 <= 0.4.14
