<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vearch:vearch:3.5.9:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avearchvearch3.5.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avearchvearch3.5.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Vearch Incorrect Authorization Vulnerability (CVE-2026-108746)</title><link>https://feed.craftedsignal.io/briefs/2026-10-vearch-auth-bypass/</link><pubDate>Sun, 11 Oct 2026 14:01:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vearch-auth-bypass/</guid><description>Vearch versions 3.5.2 through 3.5.9 contain an incorrect authorization vulnerability allowing authenticated non-root users to perform unauthorized document modifications and escalate privileges to cluster administrator.</description><content:encoded><![CDATA[<p>Vearch versions 3.5.2 through 3.5.9 are affected by an incorrect authorization vulnerability located in the Role.HasPermissionForResources function. The flaw manifests because the function fails to correctly validate or respect stored ReadOnly or None privilege levels assigned to resources within a role. Consequently, an authenticated user who is not a root administrator can bypass these restrictions to perform unauthorized upsert and delete operations on documents. Furthermore, the vulnerability enables an attacker to manipulate role permissions via the PUT /roles API to grant their own account WriteRead privileges, facilitating an escalation of access toward cluster administrator. This issue represents a significant risk to data integrity and cluster security, as it allows standard authenticated users to transcend their intended access controls within the Vearch distributed vector database environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users to read, modify, or delete sensitive data within the Vearch database regardless of assigned read-only restrictions. By leveraging the PUT /roles API, an attacker can grant themselves administrative privileges, potentially leading to full control over the Vearch cluster. This vulnerability affects all environments running Vearch versions 3.5.2 through 3.5.9.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Vearch to a version outside the affected range (3.5.2-3.5.9).</li>
<li>Implement strict network segmentation to limit access to the Vearch API, especially the /roles endpoint.</li>
<li>Review all current role and privilege assignments in the Vearch cluster for unauthorized modifications or unexpected elevated permissions.</li>
<li>Enable strict API access logging to detect unauthorized calls to the PUT /roles endpoint.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>