CVE-2026-22680 MEDIUM

CVE-2026-22680: OpenViking < 0.3.3 Missing Authorization via Task Polling

Vendor Volcengine
Product OpenViking
Weakness CWE-862 · Missing authorization
Published April 7, 2026
Last update April 8, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.

Key dates

02Disclosure timeline

April 7, 2026 CVE published
April 8, 2026 Record updated