CVE-2026-13507
Severity CVSS v4.0:
LOW
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
28/06/2026
Last modified:
29/06/2026
Description
A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of the argument ID results in insufficient verification of data authenticity. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The pull request to fix this issue awaits acceptance.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
5.00
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/volcengine/OpenViking/
- https://github.com/volcengine/OpenViking/issues/2263
- https://github.com/volcengine/OpenViking/pull/2268
- https://vuldb.com/cve/CVE-2026-13507
- https://vuldb.com/submit/838791
- https://vuldb.com/vuln/374515
- https://vuldb.com/vuln/374515/cti
- https://github.com/volcengine/OpenViking/issues/2263



