PT-2026-33478 · Unknown · Openviking
Hinotoi-Agent
·
Published
2026-04-17
·
Updated
2026-05-12
·
CVE-2026-40525
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenViking versions prior to commit c7bb167
Description
An authentication bypass exists in the VikingBot OpenAPI HTTP route surface. The issue occurs when the
api key configuration value is unset or empty, causing the authentication check to fail open. Remote attackers with network access to the exposed service can invoke privileged bot-control functionality without providing a valid 'X-API-Key' header. This allows for the submission of attacker-controlled prompts, the creation or use of bot sessions, and unauthorized access to downstream tools, integrations, secrets, or data accessible to the bot.Recommendations
Update OpenViking to commit c7bb167 or a newer version.
Ensure the
api key configuration value is properly set and not left empty.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openviking