PT-2026-47262 · Weaviate · Weaviate
Dem000
·
Published
2026-06-08
·
Updated
2026-06-08
·
CVE-2026-11500
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Weaviate versions prior to 1.38.0-rc.0
Description
An issue exists in the Static API Key Handler component within the
validateConfig() function of the usecases/auth/authentication/apikey/client.go file. Manipulation of the StaticApiKey argument allows for a remote authorization bypass. The attack complexity is high and exploitability is considered difficult.Recommendations
Upgrade to version 1.38.0-rc.0.
As a temporary workaround, restrict access to the
validateConfig() function within the Static API Key Handler to minimize the risk of exploitation.Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weaviate