CVE-2026-22207
CRITICALOpenViking <=0.1.18 - Privilege Escalation
Title source: llmDescription
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers to access administrative functions including account management, resource operations, and system configuration.
References (5)
Scores
CVSS v3
9.8
EPSS
0.0029
EPSS Percentile
52.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (3)
Volcengine/OpenViking
< 0.1.18
Volcengine/OpenViking
0251c7045b3f8092c4d2e1565115b1ba23db282f
Volcengine/OpenViking
commit 0251c70
Published
Feb 26, 2026
Tracked Since
Feb 27, 2026