{"id":"CVE-2026-22680","aliases":["GHSA-h336-2wxm-pr6q","PYSEC-2026-2855"],"url":"https://o3.security/vulnerability/CVE-2026-22680","summary":"OpenViking < 0.3.3 Missing Authorization via Task Polling","details":"OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.","published":"2026-04-07T17:08:30.835Z","modified":"2026-08-07T11:50:29.794106299Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"openviking","fixedVersion":"0.3.3"}],"fix":{"url":"https://github.com/volcengine/OpenViking/commit/8c1c3f3608364ee0bb0e45f73478771a68aebdf5","label":"volcengine/OpenViking@8c1c3f3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22680.json"},{"type":"ADVISORY","url":"https://github.com/volcengine/OpenViking/releases/tag/v0.3.3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22680"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openviking-missing-authorization-via-task-polling"},{"type":"REPORT","url":"https://github.com/volcengine/OpenViking/pull/1182"},{"type":"FIX","url":"https://github.com/volcengine/OpenViking/commit/8c1c3f3608364ee0bb0e45f73478771a68aebdf5"},{"type":"PACKAGE","url":"https://github.com/volcengine/OpenViking"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:29.794106299Z"}}