CVE-2026-22680

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.
Configurations

Configuration 1 (hide)

cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*

History

14 Apr 2026, 16:16

Type Values Removed Values Added
First Time Volcengine
Volcengine openviking
References () https://github.com/volcengine/OpenViking/commit/8c1c3f3608364ee0bb0e45f73478771a68aebdf5 - () https://github.com/volcengine/OpenViking/commit/8c1c3f3608364ee0bb0e45f73478771a68aebdf5 - Patch
References () https://github.com/volcengine/OpenViking/pull/1182 - () https://github.com/volcengine/OpenViking/pull/1182 - Exploit, Issue Tracking, Third Party Advisory
References () https://github.com/volcengine/OpenViking/releases/tag/v0.3.3 - () https://github.com/volcengine/OpenViking/releases/tag/v0.3.3 - Release Notes
References () https://www.vulncheck.com/advisories/openviking-missing-authorization-via-task-polling - () https://www.vulncheck.com/advisories/openviking-missing-authorization-via-task-polling - Third Party Advisory
CPE cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*

08 Apr 2026, 19:25

Type Values Removed Values Added
References () https://github.com/volcengine/OpenViking/pull/1182 - () https://github.com/volcengine/OpenViking/pull/1182 -

07 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 18:16

Updated : 2026-04-14 16:16


NVD link : CVE-2026-22680

Mitre link : CVE-2026-22680

CVE.ORG link : CVE-2026-22680


JSON object : View

Products Affected

volcengine

  • openviking
CWE
CWE-862

Missing Authorization