Authentication Bypass in QAnything 2.0.0 Affects Unauthenticated File Access
CVE-2026-85671
8.7HIGH
What is CVE-2026-85671?
QAnything 2.0.0 has a serious vulnerability that enables unauthenticated attackers to bypass authentication and access any uploaded file or document via two endpoints: /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc. This flaw allows attackers to enumerate file identifiers through the accessible endpoints, thereby retrieving base64-encoded files and document sections without proper verification of ownership, potentially exposing sensitive cross-tenant knowledge base content.
Affected Version(s)
QAnything 0 <= 2.0.0
