๐Ÿ” CVE Alert

CVE-2026-34999

MEDIUM 5.3

OpenViking 0.2.5 < 0.2.14 Bot Proxy Endpoints Allow Unauthenticated Access

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.

CWE CWE-306
Vendor volcengine
Product openviking
Published Apr 1, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for volcengine openviking

Be the first to know when new medium vulnerabilities affecting volcengine openviking are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Volcengine / OpenViking
0.2.5 < 0.2.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/volcengine/OpenViking/releases/tag/v0.2.14 github.com: https://github.com/volcengine/OpenViking/pull/996 github.com: https://github.com/volcengine/OpenViking/commit/27acda8d1701ff68423fbd6c902208e3c1ed9373 vulncheck.com: https://www.vulncheck.com/advisories/openviking-bot-proxy-endpoints-allow-unauthenticated-access

Credits

Chia Min Jun Lennon