🔐 CVE Alert

CVE-2026-30857

MEDIUM 5.3

WeKnora: Unauthorized Cross‑Tenant Knowledge Base Cloning

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any authenticated user to clone (duplicate) another tenant’s knowledge base into their own tenant by knowing/guessing the source knowledge base ID. This enables bulk data exfiltration (document/FAQ content) across tenants. This issue has been patched in version 0.3.0.

CWE CWE-639
Vendor tencent
Product weknora
Published Mar 7, 2026
Last Updated Mar 9, 2026
Stay Ahead of the Next One

Get instant alerts for tencent weknora

Be the first to know when new medium vulnerabilities affecting tencent weknora are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Tencent / WeKnora
< 0.3.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/Tencent/WeKnora/security/advisories/GHSA-8rf9-c59g-f82f