CVE-2026-22207: Volcengine Openviking
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers to access administrative functions including account management, resource operations, and system configuration.
Affected products
- Volcengine Openviking: up to and including 0.1.18
Published 2026-02-26. Last modified 2026-06-17.