Vendor
Vearch versions 3.5.2 through 3.5.9 contain an incorrect authorization vulnerability allowing authenticated non-root users to perform unauthorized document modifications and escalate privileges to cluster administrator.