{"id":"CVE-2026-108746","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-108746","summary":"Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed…","details":"Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.","published":"2026-10-11T13:17:19.230","modified":"2026-10-11T13:17:19.230","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/vearch/vearch"},{"type":"WEB","url":"https://github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/entity/user.go#L300-L313"},{"type":"WEB","url":"https://github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/master/services/role_service.go#L180-L229"},{"type":"WEB","url":"https://hackmd.io/@haind/vearch-rbac-privilege-level-ignored-authz-bypass"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vearch-3.5.2-through-3.5.9-incorrect-authorization-via-role-haspermissionforresources"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-11T13:17:19.230"}}