CVE-2026-25628
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.
Vendor
Product
CWE
Yayın Tarihi
2026-02-06 21:16:18
Güncelleme
2026-02-19 17:45:58
Source Identifier
security-advisories@github.com
KEV Date Added
-