CVE-2026-30859 describes a broken access control vulnerability in WeKnora, an LLM-powered framework, affecting versions prior to 0.2.12. This flaw allows any authenticated tenant to bypass tenant isolation and access sensitive data, such as API keys, model configurations, and private messages, belonging to other tenants. With a CVSS score of 5.3 (Medium), the vulnerability has a network attack vector, high confidentiality impact, and low privileges required, but high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.12CPE matchmatch criteria | cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.