Tencent WeKnora Config API Endpoint Authorization Bypass Vulnerability

Vulnerability

An authorization bypass vulnerability has been identified in Tencent WeKnora versions through 0.3.6. The issue resides in the Config API Endpoint, specifically within the 'getKnowledgeBaseForInitialization' function in 'internal/handler/initialization.go'. This vulnerability allows authenticated users to bypass authorization and access or modify Knowledge Base configurations of other tenants. The flaw can be exploited remotely, leading to unauthorized cross-tenant data access and manipulation.

Impact

Exploitation of this vulnerability allows for unauthorized reading and modification of Knowledge Base configurations across different tenants, potentially disrupting knowledge base operations and causing logical inconsistencies.

Reproduction

To reproduce this vulnerability, register two users: one as the victim and the other as the attacker. The attacker can then use the victim's Knowledge Base ID to read and modify its configuration through the vulnerable API endpoints, bypassing authorization checks.

Added: May 18, 2026, 4:19 AM
Updated: May 18, 2026, 4:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.6
remediation
0.0
relevance
8.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.