Home

Description

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers to access administrative functions including account management, resource operations, and system configuration.

PUBLISHED Reserved 2026-01-06 | Published 2026-02-26 | Updated 2026-02-26 | Assigner VulnCheck




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unaffected

Any version
affected

commit 0251c70
unaffected

Credits

Chia Min Jun Lennon finder

References

github.com/volcengine/OpenViking/issues/302 issue-tracking

github.com/volcengine/OpenViking/pull/310 vendor-advisory

github.com/...anges/0251c7045b3f8092c4d2e1565115b1ba23db282f patch

www.vulncheck.com/...ot-api-key-allows-anonymous-root-access third-party-advisory

cve.org (CVE-2026-22207)

nvd.nist.gov (CVE-2026-22207)

Download JSON