Junglewise Threat Intelligence

CVE-2026-8786: Tencent WeKnora authorization bypass in Config API Endpoint

CVE-2026-8786 · Severity: medium · CVSS 6.3 · Published 2026-05-18

Vendors: Tencent.

Executive brief

Tencent WeKnora is a knowledge base management system. A security flaw allows any registered user to view or modify the configuration of knowledge bases belonging to other users or organizations. This could lead to the unauthorized disclosure of sensitive configuration data or the disruption of knowledge base operations across different tenants.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the InitializationHandler of Tencent WeKnora up to version 0.3.6. The function 'getKnowledgeBaseForInitialization' in 'internal/handler/initialization.go' retrieves knowledge base entities using only the 'kbId' without verifying if the entity belongs to the requesting user's 'TenantID'. An authenticated attacker can exploit this by sending crafted GET, PUT, or POST requests to the '/api/v1/initialization/config/{kbId}' or '/api/v1/initialization/kb/{kbId}' endpoints. This allows the attacker to read or modify configurations such as chunk sizes, separators, and LLM models for any knowledge base on the system.

Affected products

  • Tencent WeKnora up to 0.3.6

Timeline

  • 2026-04-06: disclosed: Public exploit and advisory published on GitHub Gist
  • 2026-05-18: advisory: NVD and VulDB publish advisory details

References

Related threats