OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed service can invoke privileged bot-control functionality without providing a valid X-API-Key header, including submitting attacker-controlled prompts, creating or using bot sessions, and accessing downstream tools, integrations, secrets, or data accessible to the bot.
References
| Link | Resource |
|---|---|
| https://github.com/volcengine/OpenViking/commit/c7bb1676f4d037609f041bf39e4e2bd52e8f9820 | Patch |
| https://github.com/volcengine/OpenViking/pull/1447 | Exploit Patch Vendor Advisory |
| https://github.com/volcengine/OpenViking/releases/tag/v0.3.9 | Release Notes |
| https://www.vulncheck.com/advisories/openviking-authentication-bypass-via-vikingbot-openapi | Third Party Advisory |
Configurations
History
05 May 2026, 18:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:* | |
| First Time |
Volcengine
Volcengine openviking |
|
| References | () https://github.com/volcengine/OpenViking/commit/c7bb1676f4d037609f041bf39e4e2bd52e8f9820 - Patch | |
| References | () https://github.com/volcengine/OpenViking/pull/1447 - Exploit, Patch, Vendor Advisory | |
| References | () https://github.com/volcengine/OpenViking/releases/tag/v0.3.9 - Release Notes | |
| References | () https://www.vulncheck.com/advisories/openviking-authentication-bypass-via-vikingbot-openapi - Third Party Advisory |
21 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed service can invoke privileged bot-control functionality without providing a valid X-API-Key header, including submitting attacker-controlled prompts, creating or using bot sessions, and accessing downstream tools, integrations, secrets, or data accessible to the bot. | |
| References |
|
17 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-17 19:16
Updated : 2026-05-05 18:06
NVD link : CVE-2026-40525
Mitre link : CVE-2026-40525
CVE.ORG link : CVE-2026-40525
JSON object : View
Products Affected
volcengine
- openviking
CWE
CWE-636
Not Failing Securely ('Failing Open')
