HarborGuard / CVE
Back to search
CRITICALCVE-2026-40525Published Modified CNA VulnCheck

CVE-2026-40525: OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI

OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed service can invoke privileged bot-control functionality without providing a valid X-API-Key header, including submitting attacker-controlled prompts, creating or using bot sessions, and accessing downstream tools, integrations, secrets, or data accessible to the bot.

Metrics

CVSS v4.0
9.1
Severity
CRITICAL
Fixed in
0.3.9
Affected Products
1

Fix available

0.3.9c7bb1676f4d037609f041bf39e4e2bd52e8f9820
Patch commits
Affected packages
  • volcengine / OpenViking
    < 0.3.9 (from 0)
    Fixed in c7bb1676f4d037609f041bf39e4e2bd52e8f9820
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N