CVE Explorer
CVE-2026-30859
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated tenant to read sensitive data belonging to other tenants, including API keys, model configurations, and private messages. The application fails to enforce tenant isolation on critical tables (models, messages, embeddings), enabling unauthorized cross-tenant data access with user-leve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"WeKnora","vendor":"Tencent","versions":[{"status":"affected","version":"< 0.2.12"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:967525f17187cdcb01974f572406efd875bbfd18ca9895e606463a3f6654cc95 · sha256:1cfffc538dd22d91… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:967525f17187cdcb01974f572406efd875bbfd18ca9895e606463a3f6654cc95 · sha256:1cfffc538dd22d91… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:967525f17187cdcb01974f572406efd875bbfd18ca9895e606463a3f6654cc95 · sha256:1cfffc538dd22d91… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/Tencent/WeKnora/security/advisories/GHSA-2f4c-vrjq-rcgv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Tencent/WeKnora/security/advisories/GHSA-2f4c-vrjq-rcgv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:967525f17187cdcb01974f572406efd875bbfd18ca9895e606463a3f6654cc95 · sha256:1cfffc538dd22d91… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.