Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59093— Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment

Quick assessment

Affected
weaviate weaviate
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weaviate是Weaviate公司开源的一个开源矢量数据库。 Weaviate 1.38.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在RBAC角色分配时未验证执行分配的主体是否持有被分配角色所授予的权限,导致持有delegated assign_and_revoke_users或assign_and_revoke_groups权限的用户可将内置管理员角色或高权限自定义角色分配给自身或其他用户,从而完全控制数据库。

CVSS 8.8 · High EPSS 0.71% · P51

Possible ATT&CK Techniques 1 AI

T1078.004 · Cloud Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
weaviate weaviate < 1.38.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59093

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment
Source: CVE Program / CVE List V5
Vulnerability Description
Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) authorize only that the caller may assign roles to the target user or group, not the permissions contained in the assigned roles, unlike role creation which enforces that a user can only create roles with permissions less than or equal to its own. A user holding only the delegated assign_and_revoke_users or assign_and_revoke_groups permission can assign the built-in admin role, or any high-privilege custom role, to itself or others, escalating to full administrative control of the database.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
Source: CVE Program / CVE List V5
Vulnerability Title
Weaviate 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Weaviate是Weaviate公司开源的一个开源矢量数据库。 Weaviate 1.38.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在RBAC角色分配时未验证执行分配的主体是否持有被分配角色所授予的权限,导致持有delegated assign_and_revoke_users或assign_and_revoke_groups权限的用户可将内置管理员角色或高权限自定义角色分配给自身或其他用户,从而完全控制数据库。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
weaviate weaviate 0 ~ 1.38.0 -

II. Public POCs for CVE-2026-59093

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7694 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-59093

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-59093 (2)

Vendor Advisories for CVE-2026-59093 (1)

Vendor Pages for CVE-2026-59093 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-59093

No comments yet


Leave a comment