SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75480

MEDIUM · CVSS 6.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users to access all co-tenant records due to insufficient user-level access controls on the OpenViking debug vector scroll and count endpoints. This can lead to unauthorized disclosure of sensitive information, such as private memories and resources, from other users within the same account. Organizations utilizing OpenViking should prioritize addressing this issue to protect user data from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75480
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.