HarborGuard / CVE
Back to search
CRITICALCVE-2026-22207Published Modified CNA VulnCheck

CVE-2026-22207: OpenViking Missing root_api_key Allows Anonymous ROOT Access

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers to access administrative functions including account management, resource operations, and system configuration.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
0251c7045b3f8092c4d2e1565115b1ba23db282f
Affected Products
1

Fix available

0251c7045b3f8092c4d2e1565115b1ba23db282f
Patch commits
Affected packages
  • Volcengine / OpenViking
    ≤ 0.1.18
    Fixed in 0251c7045b3f8092c4d2e1565115b1ba23db282f
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N