
Another reminder that trust is earned, not assumed. CVE-2026-59093. Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions... The best defense is the one you set up before you needed it.
Post summary
The message highlights that Weaviate versions earlier than 1.38.0 lack a permission check for RBAC role assignments, implying a potential privilege‑escalation vulnerability in that product.

