CVE-2026-30855Patch(tencent / weknora)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tencent weknora systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the public, this vulnerability allows any unauthenticated attacker to register an account and subsequently exploit the system. This enables cross-tenant account takeover and destruction, making the impact critical. This issue has been patched in version 0.3.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weknora

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-07); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
weknora

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-07: 3Mentions · 2026-03-08: 1Mentions · 2026-03-12: 1Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-23: 103-0703-0803-1203-23
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-073
Disclosure1Patch2
2026-03-081
Disclosure1
2026-03-121
General1
2026-03-231
Patch1
Full discourse6 posts
  • PulsePatch.io@pulsepatchio
    Patch

    Broken access control in `WeKnora` tenant management (CVE-2026-30855) allows unauthorized access. Investigate usage & apply vendor guidance for this #critical #accesscontrol flaw. #infosec https://www.pulsepatch.io/posts/cve-2026-30855-weknora-broken-access-control

    Post summary

    The tweet highlights a critical broken access control flaw in WeKnora and urges readers to consult vendor guidance to mitigate the vulnerability.

    0000024
    2 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-30855 (CVSS:8.8, HIGH) is Analyzed. WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0...https://nvd.nist.gov/vuln/detail/CVE-2026-30855 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post simply notes that CVE‑2026‑30855, rated high, has been analyzed and points to the NVD entry for further details.

    0000019
    172 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30855 - High WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora ... https://www.thehackerwire.com/vulnerability/CVE-2026-30855/ https://t.co/gTVIkjdwRj

    Post summary

    The tweet announces CVE-2026-30855, describing an authorization bypass in WeKnora’s tenant management endpoints before v0.3.2, with a link to a detailed vulnerability report.

    0000037
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30855 Authorization Bypass in WeKnora Framework Enables Cross-Tenant Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30855

    Post summary

    The text announces the disclosure of CVE-2026-30855, an authorization bypass in WeKnora that enables cross‑tenant account takeover.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-30855 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant managem… https://www.cve.org/CVERecord?id=CVE-2026-30855

    Post summary

    The note reports an authorization bypass vulnerability in WeKnora, indicating the issue was fixed in version 0.3.2 and offering a clear patch reference, but it lacks any PoC, exploit code, or active exploitation claims.

    0000079
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30855: HIGH] Critical vulnerability in WeKnora application (pre 0.3.2) allows account takeover and destruction due to an authorization bypass. Ensure to update to version 0.3.2 for patched fix.#cve,CVE-2026-30855,#cybersecurity https://cvefind.com/CVE-2026-30855

    Post summary

    The advisory announces CVE‑2026‑30855, an authorization bypass in WeKnora that enables account takeover, and recommends upgrading to version 0.3.2 for the fix.

    0000045
    599 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptencentweknora---

Explore more