CVE-2026-22680 is a missing authorization vulnerability affecting OpenViking versions prior to 0.3.3. The flaw exists in the task polling endpoints (/api/v1/tasks and /api/v1/tasks/{task_id}), which lack proper authentication controls, allowing unauthenticated attackers to enumerate and retrieve background task metadata belonging to other users. Exposed data includes task type, status, resource identifiers, archive URIs, result payloads, and error information, with particular concern for cross-tenant interference in multi-tenant environments. The vulnerability has a CVSS v3.1 score of 5.3 (Medium severity) with a network-based attack vector requiring low complexity and no user interaction. Attack success does not require any privileges. The impact is limited to confidentiality, with no effect on integrity or availability. The EPSS score of 0.0008 indicates this vulnerability is currently not a widespread threat compared to other disclosed vulnerabilities. There is no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, and it is marked as inactive on the Hot List, suggesting minimal community attention or public exploit code availability at this time. Organizations running affected versions should prioritize upgrading to 0.3.3 or later as part of routine patch management.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.3CPE matchmatch criteria | cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:* | ||
>= 0, < 0.3.3CPE match | cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.