CVE-2026-108746
Description
Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/vearch/vearch
- https://github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/entity/user.go#L300-L313
- https://github.com/vearch/vearch/blob/bae78b189ff0ab1d8ac659c6acaeeb5f630db33f/internal/master/services/role_service.go#L180-L229
- https://hackmd.io/@haind/vearch-rbac-privilege-level-ignored-authz-bypass
- https://www.vulncheck.com/advisories/vearch-3.5.2-through-3.5.9-incorrect-authorization-via-role-haspermissionforresources
CWEs
CWE-863
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.