CVE-2026-34999 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to…
Medium CVSS: 6.9

CVE-2026-34999

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.
Vendor
-
Product
-
CWE
CWE-306
Yayın Tarihi
2026-04-01 14:16:55
Güncelleme
2026-04-01 16:23:50
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar