CVE-2026-75480: Volcengine Openviking

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.

Affected products

Published 2026-08-17. Last modified 2026-09-24.