CVE-2026-75480
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
17/08/2026
Last modified:
17/08/2026
Description
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM



