PT-2026-47262 · Weaviate · Weaviate

·

CVE-2026-11500

·

Published

2026-06-08

·

Updated

2026-09-04

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Weaviate versions prior to 1.38.0-rc.0
Description An issue exists in the Static API Key Handler component within the validateConfig() function of the usecases/auth/authentication/apikey/client.go file. Manipulation of the StaticApiKey argument allows for a remote authorization bypass. The attack complexity is high and exploitability is considered difficult.
Recommendations Upgrade to version 1.38.0-rc.0. As a temporary workaround, restrict access to the validateConfig() function within the Static API Key Handler to minimize the risk of exploitation.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11500
GHSA-JQPM-WF57-QX5C
GO-2026-6140
OPENSUSE-SU-2026:21761-1

Affected Products

Weaviate