WeKnora Broken Access Control Vulnerability Allowing Cross-Tenant Data Exposure

Vulnerability

A broken access control vulnerability has been identified in WeKnora versions prior to 0.2.12. This vulnerability allows authenticated tenants to access sensitive data from other tenants, including API keys, model configurations, and private messages. The issue arises because the application does not properly enforce tenant isolation on critical tables, enabling unauthorized data access with user-level authentication. The vulnerability has been patched in version 0.2.12.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data across different tenant accounts, including API keys, private messages, and model configurations. This breach of data privacy and security could have serious implications, especially if exposed information includes authentication credentials or confidential business communications.

Reproduction

To reproduce this vulnerability, authenticate as a tenant and use the database_query tool to execute SQL queries targeting the 'models' or 'messages' tables. The absence of tenant isolation will allow access to all records from these tables across different tenants, bypassing privacy controls.

Remediation

Users are advised to update WeKnora to version 0.2.12 or later, where this vulnerability has been patched.

Added: Mar 7, 2026, 5:18 PM
Updated: Mar 7, 2026, 5:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.