CVE-2026-30855 is an authorization bypass vulnerability in WeKnora, an LLM-powered framework, affecting versions prior to 0.3.2. This flaw allows any authenticated user to read, modify, or delete any tenant by ID. Given open account registration, an unauthenticated attacker can register, then exploit this to achieve cross-tenant account takeover and destruction. The vulnerability has a CVSS score of 8.8 (High), indicating a critical impact with high confidentiality, integrity, and availability concerns, requiring only low privileges and no user interaction for exploitation. It is a network-based attack with low complexity. There is no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered some community discussion, with two mentions on social media platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.2CPE matchmatch criteria | cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.