CVE 9.1 CRITICAL

OpenViking Authentication Bypass via VikingBot OpenAPI_CVE-2026-40525

9.1 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

OpenViking prior to commit c7bb167 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed service can invoke privileged bot-control functionality without providing a valid X-API-Key header, including submitting attacker-controlled prompts, creating or using bot sessions, and accessing downstream tools, integrations, secrets, or data accessible to the bot.

AI Analysis

Authentication bypass vulnerability in VikingBot OpenAPI HTTP route surface

Basic Information

ID CVE-2026-40525
Source VulnCheck
Published Apr 17, 2026 at 18:19

Affected Product

Vendor volcengine
Product OpenViking
Affected Versions volcengine OpenViking 0

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity CRITICAL
Vendor volcengine
Product OpenViking

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.