<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:00:01.313321+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274993</id>
    <title>EUVD-2026-274993</title>
    <updated>2026-10-06T05:00:01.359687+00:00</updated>
    <content>EUVD-2026-274993</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30855</id>
    <title>fkie_cve-2026-30855</title>
    <updated>2026-10-06T05:00:01.359725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical. This issue has been patched in version 0.3.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30855"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ccj6-79j6-cq5q</id>
    <title>GHSA-ccj6-79j6-cq5q — WeKnora Vulnerable to Broken Access Control in Tenant Management</title>
    <updated>2026-10-06T05:00:01.359759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/Tencent/WeKnora</p>
<p>### Summary
An authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical.</p>
<p>### Details
The tenant management handlers do not validate that the caller owns the tenant or has cross-tenant privileges. The handlers parse the tenant ID from the path and directly call the service layer with that ID, returning or mutating the tenant without authorization checks.</p>
<p>Affected handlers:
- `GET /api/v1/tenants` lists all tenants without ownership checks
- `GET /api/v1/tenants/{id}` reads any tenant by ID without ownership checks
- `PUT /api/v1/tenants/{id}` allows updating any tenant by ID without ownership checks
- `DELETE /api/v1/tenants/{id}` allows deleting any tenant by ID without ownership checks</p>
<p>These endpoints do not enforce cross-tenant permissions or deny-by-default behavior, unlike `ListAllTenants` and `SearchTenants`.</p>
<p>### PoC
1) Register a new account as a user in Tenant 10025 and obtain a bearer token or API key.</p>
<p>2) Read details of other tenants:</p>
<p>- Request that uses API key via the `X-API-Key` header:</p>
<p>```http
    GET /api/v1/tenants HTTP/1.1
    Host: localhost
    Connection: keep-alive
    X-Request-ID: 2TpH2S0sHyi1
    X-AP…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ccj6-79j6-cq5q"/>
  </entry>
</feed>
