CVE-2026-11466

A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

07 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-07 23:16

Updated : 2026-06-08 14:57


NVD link : CVE-2026-11466

Mitre link : CVE-2026-11466

CVE.ORG link : CVE-2026-11466


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control