GHSA-73v4-h56h-crx9HighCVSS 8.8
Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role...
🔗 CVE IDs covered (1)
📋 Description
Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-108746
- https://github.com/vearch/vearch
- https://github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/entity/user.go#L300-L313
- https://github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/master/services/role_service.go#L180-L229
- https://hackmd.io/@haind/vearch-rbac-privilege-level-ignored-authz-bypass
- https://www.vulncheck.com/advisories/vearch-3.5.2-through-3.5.9-incorrect-authorization-via-role-haspermissionforresources
- https://github.com/advisories/GHSA-73v4-h56h-crx9