| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-ccj6-79j6-cq5q | WeKnora Vulnerable to Broken Access Control in Tenant Management |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:* |
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tencent
Tencent weknora |
|
| Vendors & Products |
Tencent
Tencent weknora |
Sat, 07 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical. This issue has been patched in version 0.3.2. | |
| Title | WeKnora: Broken Access Control in Tenant Management | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T18:24:39.227Z
Reserved: 2026-03-05T21:27:35.342Z
Link: CVE-2026-30855
Updated: 2026-03-09T17:58:56.726Z
Status : Analyzed
Published: 2026-03-07T17:15:53.053
Modified: 2026-03-09T17:33:08.627
Link: CVE-2026-30855
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:04:55Z
Github GHSA