CVE-2026-75480

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
17/08/2026
Last modified:
17/08/2026

Description

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.