OVERVIEW CVE-2026-40525 is an authentication bypass vulnerability affecting OpenViking versions prior to 0.3.9. The flaw exists in the VikingBot OpenAPI HTTP route handler, where the authentication mechanism fails to enforce security checks when the api_key configuration parameter is unset or empty. This allows unauthenticated remote attackers to access privileged bot-control functionality. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring low complexity and no user interaction or special privileges. The impact is severe, as successful exploitation grants attackers the ability to submit arbitrary prompts, create or hijack bot sessions, and access sensitive downstream resources including tools, integrations, secrets, and data. While confidentiality and integrity are fully compromised, availability is not directly impacted. EXPLOITATION STATUS The vulnerability is currently marked as active on the Hot List, indicating active exploitation in the wild. However, the EPSS score of 0.0014 suggests relatively lower probability of exploitation compared to other vulnerabilities. The CVE has not yet been added to the Known Exploited Vulnerabilities (KEV) catalog. Organizations running OpenViking should immediately upgrade to version 0.3.9 or later and ensure api_key configuration values are properly set to mitigate exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.9CPE matchmatch criteria | cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:* | ||
>= 0, < 0.3.9CPE match | cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.