{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/odysseus/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-70619"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Odysseus"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","vulnerability","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["Odysseus"],"content_html":"\u003cp\u003eOdysseus versions prior to commit bf325f6 contain a critical missing authorization vulnerability (CVE-2026-70619). The issue exists within the application's endpoint management routes, which verify that a user has an active session but fail to enforce administrative privileges. By targeting these specific routes, an authenticated non-admin user can manipulate the server-wide embedding backend configuration.\u003c/p\u003e\n\u003cp\u003eAn attacker can overwrite the configuration file and the process environment with a malicious URL. This allows the redirection of all subsequent embedding-related traffic, including chat messages, RAG (Retrieval-Augmented Generation) queries, memory entries, and vault text, to an attacker-controlled destination. Alternatively, an attacker can delete the configuration entirely, resulting in a denial-of-service condition for the embedding functionality. This vulnerability poses a significant risk to data confidentiality and integrity, as it facilitates unauthorized access to sensitive user data and enterprise RAG context.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the exfiltration of sensitive RAG data and chat content, potentially exposing intellectual property or PII handled by the embedding backend. Organizations using affected versions of Odysseus are at risk of data leakage and service disruption. The severity is marked as high (CVSS 8.8) given the ease of exploitation for any authenticated user.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Odysseus to commit bf325f6 or higher to resolve the authorization logic flaw.\u003c/li\u003e\n\u003cli\u003eAudit application access logs for any unauthorized POST or DELETE requests targeting endpoint configuration management routes initiated by non-administrative service or user accounts.\u003c/li\u003e\n\u003cli\u003eReview current embedding backend configurations to ensure no unexpected or unauthorized URLs have been persisted in the application environment or configuration files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T00:03:00Z","date_published":"2026-08-05T00:03:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-odysseus-auth-bypass/","summary":"Authenticated non-admin users in Odysseus versions prior to commit bf325f6 can exploit a missing authorization vulnerability to modify server-wide embedding backend settings and intercept sensitive data.","title":"Authorization Bypass Vulnerability in Odysseus Embedding Configuration","url":"https://feed.craftedsignal.io/briefs/2026-08-odysseus-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Odysseus","version":"https://jsonfeed.org/version/1.1"}