Executive brief
Weaviate is an open-source vector database used for AI and search applications. A security flaw in its access control system allows users with limited administrative permissions to grant themselves or others full administrative control over the database. This could lead to unauthorized access to sensitive data, data modification, or complete service disruption.
Technical details
A privilege escalation vulnerability exists in Weaviate's RBAC implementation prior to version 1.38.0. The 'assignRoleToUser' and 'assignRoleToGroup' handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) fail to verify that the caller possesses the permissions contained within the role they are assigning. While role creation enforces that a user can only create roles with permissions less than or equal to their own, the assignment handlers only check if the caller has the general 'assign_and_revoke' permission. Consequently, a low-privileged user with assignment rights can assign the built-in 'admin' role to themselves, gaining full control of the database. This issue is resolved in version 1.38.0.
Affected products
- Weaviate Weaviate before 1.38.0
Timeline
- 2026-05-28: patched: Fix merged into main branch via pull request 11493
- 2026-06-05: advisory: Version 1.38.0 released containing the fix
- 2026-07-02: disclosed: CVE-2026-59093 published
References
- https://github.com/weaviate/weaviate/commit/2c75f6fb217631f7751c4b2a7d37a488cef13edb
- https://github.com/weaviate/weaviate/pull/11493
- https://github.com/weaviate/weaviate/releases/tag/v1.38.0
- https://www.vulncheck.com/advisories/weaviate-privilege-escalation-via-unchecked-permissions-in-rbac-role-assignment