Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h336-2wxm-pr6q | OpenViking contains a missing authorization vulnerability in the task polling endpoints |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:* |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Volcengine
Volcengine openviking |
|
| Vendors & Products |
Volcengine
Volcengine openviking |
|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments. | |
| Title | OpenViking < 0.3.3 Missing Authorization via Task Polling | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-08T18:49:10.725Z
Reserved: 2026-01-08T19:04:26.365Z
Link: CVE-2026-22680
Updated: 2026-04-08T18:48:59.171Z
Status : Analyzed
Published: 2026-04-07T18:16:38.853
Modified: 2026-04-14T16:16:31.870
Link: CVE-2026-22680
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:30:09Z
Github GHSA