<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:59:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274993</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274993</link>
      <description>EUVD-2026-274993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274993</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30855</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30855</link>
      <description>&lt;p&gt;WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical. This issue has been patched in version 0.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical. This issue has been patched in version 0.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30855</guid>
    </item>
    <item>
      <title>GHSA-ccj6-79j6-cq5q — WeKnora Vulnerable to Broken Access Control in Tenant Management</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ccj6-79j6-cq5q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/Tencent/WeKnora&lt;/p&gt;
&lt;p&gt;### Summary
An authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical.&lt;/p&gt;
&lt;p&gt;### Details
The tenant management handlers do not validate that the caller owns the tenant or has cross-tenant privileges. The handlers parse the tenant ID from the path and directly call the service layer with that ID, returning or mutating the tenant without authorization checks.&lt;/p&gt;
&lt;p&gt;Affected handlers:
- `GET /api/v1/tenants` lists all tenants without ownership checks
- `GET /api/v1/tenants/{id}` reads any tenant by ID without ownership checks
- `PUT /api/v1/tenants/{id}` allows updating any tenant by ID without ownership checks
- `DELETE /api/v1/tenants/{id}` allows deleting any tenant by ID without ownership checks&lt;/p&gt;
&lt;p&gt;These endpoints do not enforce cross-tenant permissions or deny-by-default behavior, unlike `ListAllTenants` and `SearchTenants`.&lt;/p&gt;
&lt;p&gt;### PoC
1) Register a new account as a user in Tenant 10025 and obtain a bearer token or API key.&lt;/p&gt;
&lt;p&gt;2) Read details of other tenants:&lt;/p&gt;
&lt;p&gt;- Request that uses API key via the `X-API-Key` header:&lt;/p&gt;
&lt;p&gt;```http
    GET /api/v1/tenants HTTP/1.1
    Host: localhost
    Connection: keep-alive
    X-Request-ID: 2TpH2S0sHyi1
    X-AP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/Tencent/WeKnora&lt;/p&gt;
&lt;p&gt;### Summary
An authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical.&lt;/p&gt;
&lt;p&gt;### Details
The tenant management handlers do not validate that the caller owns the tenant or has cross-tenant privileges. The handlers parse the tenant ID from the path and directly call the service layer with that ID, returning or mutating the tenant without authorization checks.&lt;/p&gt;
&lt;p&gt;Affected handlers:
- `GET /api/v1/tenants` lists all tenants without ownership checks
- `GET /api/v1/tenants/{id}` reads any tenant by ID without ownership checks
- `PUT /api/v1/tenants/{id}` allows updating any tenant by ID without ownership checks
- `DELETE /api/v1/tenants/{id}` allows deleting any tenant by ID without ownership checks&lt;/p&gt;
&lt;p&gt;These endpoints do not enforce cross-tenant permissions or deny-by-default behavior, unlike `ListAllTenants` and `SearchTenants`.&lt;/p&gt;
&lt;p&gt;### PoC
1) Register a new account as a user in Tenant 10025 and obtain a bearer token or API key.&lt;/p&gt;
&lt;p&gt;2) Read details of other tenants:&lt;/p&gt;
&lt;p&gt;- Request that uses API key via the `X-API-Key` header:&lt;/p&gt;
&lt;p&gt;```http
    GET /api/v1/tenants HTTP/1.1
    Host: localhost
    Connection: keep-alive
    X-Request-ID: 2TpH2S0sHyi1
    X-AP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ccj6-79j6-cq5q</guid>
    </item>
  </channel>
</rss>
