


Perceptive Security
SOC/SIEM Consultancy

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend …
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 23:03:20
Source:
nvd.nist.gov
Identity & Access, Web Technologies, Data Breach & Exfiltration
CVE-2026-70619 is a missing authorization vulnerability in Odysseus (before commit bf325f6) that allows authenticated non-admin users to manage server-wide embedding backend configuration. The affected endpoint routes verify session authentication but fail to enforce admin authorization guards. An attacker can supply a malicious URL to overwrite the embedding backend configuration, causing all subsequent embedding operations—including chat messages, RAG queries, memory entries, and vault text—to be transmitted in plaintext to an attacker-controlled destination. Alternatively, an attacker can delete the endpoint configuration entirely, denying embedding service to all users. The vulnerability affects the configuration file and process environment. A fix was introduced in commit bf325f6b2185cb42bc5d8f5713a64aecffb766d4. The issue has been documented in GitHub issues and a public blog post, and is tracked by VulnCheck.
Technical details
Mitigation steps:
Affected products:
Odysseus
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70619
https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/
https://github.com/odysseus-dev/odysseus/commit/bf325f6b2185cb42bc5d8f5713a64aecffb766d4
https://github.com/odysseus-dev/odysseus/issues/132
https://github.com/odysseus-dev/odysseus/issues/80
https://www.vulncheck.com/advisories/odysseus-missing-admin-authorization-via-embedding-endpoint-routes
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
