CyberRota Analysis
AI-GeneratedThe vulnerability allows authenticated users to access all co-tenant records due to insufficient user-level access controls on the OpenViking debug vector scroll and count endpoints. This can lead to unauthorized disclosure of sensitive information, such as private memories and resources, from other users within the same account. Organizations utilizing OpenViking should prioritize addressing this issue to protect user data from potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.