github.com
https://github.com/Tencent/WeKnora CVE-2026-30857
MEDIUM
WeKnora: Unauthorized Cross‑Tenant Knowledge Base Cloning
Record summary
CVE-2026-30857 has a selected CVSS score of 5.3 (medium).
Description
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any authenticated user to clone (duplicate) another tenant’s knowledge base into their own tenant by knowing/guessing the source knowledge base ID. This enables bulk data exfiltration (document/FAQ content) across tenants. This issue has been patched in version 0.3.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 9, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WeKnoraBrowse Tencent / WeKnora | CVE List | < 0.3.0 | affected |
github.com/Tencent/WeKnoraBrowse Go / github.com/Tencent/WeKnora | GitHub Advisory | Before 0.3.0 · Fixed in 0.3.0 | affected |
References
3github.comConfirmation
https://github.com/Tencent/WeKnora/security/advisories/GHSA-8rf9-c59g-f82f nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-30857