GHSA-73v4-h56h-crx9HighCVSS 8.8

Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role...

Published
October 11, 2026
Last Modified
October 11, 2026

🔗 CVE IDs covered (1)

📋 Description

Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.

🔗 References (7)