8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.
AI Analysis
Arbitrary file write via /logger endpoint
Basic Information
ID
CVE-2026-25628
Source
GitHub_M
Published
Feb 6, 2026 at 20:44
Modified
Feb 6, 2026 at 21:11
Affected Product
Vendor
qdrant
Product
qdrant
Version
>= 1.9.3, < 1.16.0
Affected Versions
qdrant qdrant >= 1.9.3, < 1.16.0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Qdrant
Product
Qdrant
Version
1.9.3 to 1.16.0