Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40525

33
FAUCET Score

OVERVIEW CVE-2026-40525 is an authentication bypass vulnerability affecting OpenViking versions prior to 0.3.9. The flaw exists in the VikingBot OpenAPI HTTP route handler, where the authentication mechanism fails to enforce security checks when the api_key configuration parameter is unset or empty. This allows unauthenticated remote attackers to access privileged bot-control functionality. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring low complexity and no user interaction or special privileges. The impact is severe, as successful exploitation grants attackers the ability to submit arbitrary prompts, create or hijack bot sessions, and access sensitive downstream resources including tools, integrations, secrets, and data. While confidentiality and integrity are fully compromised, availability is not directly impacted. EXPLOITATION STATUS The vulnerability is currently marked as active on the Hot List, indicating active exploitation in the wild. However, the EPSS score of 0.0014 suggests relatively lower probability of exploitation compared to other vulnerabilities. The CVE has not yet been added to the Known Exploited Vulnerabilities (KEV) catalog. Organizations running OpenViking should immediately upgrade to version 0.3.9 or later and ensure api_key configuration values are properly set to mitigate exposure.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.3.9CPE matchmatch criteria
cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*
>= 0, < 0.3.9CPE match
cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.1CRITICAL

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 24th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: openvikingFixed in: 0.3.9

Vendor Advisories (1)

pipGHSA-jgq2-vq69-gr6hcritical

OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes

Apr 17, 2026

References

github.com / volcengine/OpenViking/commit/c7bb1676f4d037609f041bf39e4e2bd52e8f9820
Patch
github.com / volcengine/OpenViking/pull/1447
ExploitPatchVendor Advisory
github.com / volcengine/OpenViking/releases/tag/v0.3.9
Release Notes
vulncheck.com / advisories/openviking-authentication-bypass-via-vikingbot-openapi
Third Party Advisory