CVE-2026-108746
Received Received - Intake

Incorrect Authorization in Vearch Allows Privilege Escalation to Cluster Admin

Vulnerability report for CVE-2026-108746, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Vearch vearch 3.5.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Vearch versions 3.5.2 through 3.5.9 have an authorization flaw in Role.HasPermissionForResources. The system incorrectly ignores stored ReadOnly or None privilege levels for resources assigned to a role. This allows authenticated non-root users to bypass intended restrictions and perform unauthorized actions such as upserting or deleting documents, or escalating their role privileges to WriteRead or higher.

Detection Guidance

To detect this vulnerability, check Vearch versions between 3.5.2 and 3.5.9 for unauthorized privilege escalation attempts. Review role permissions and audit logs for non-root users performing write operations despite ReadOnly or None privileges. Inspect the Role.HasPermissionForResources function logic for incorrect privilege checks.

Impact Analysis

If you use Vearch 3.5.2 to 3.5.9, an attacker with basic authenticated access could manipulate data, delete records, or gain elevated privileges within your cluster. This could lead to data corruption, unauthorized access to sensitive information, or full administrative control over the system.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized data access, modification, or deletion. GDPR requires protecting personal data integrity and access controls, while HIPAA mandates strict access controls for protected health information. Exploitation could result in data breaches, unauthorized disclosures, or failure to maintain audit trails.

Mitigation Strategies

Upgrade Vearch to a version beyond 3.5.9 where the authorization vulnerability is fixed. Review role permissions to ensure no unauthorized privilege escalation exists. Restrict non-root user access to sensitive operations until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108746. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart