By vendor

Weaviate vulnerabilities

Known CVEs affecting Weaviate products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-59093HIGH 8.8

    Weaviate has a privilege escalation vulnerability in its role-based access control (RBAC) system. When assigning roles to users or groups, the system fails to check whether the person doing the assigning actually has the permissions they're trying to grant. This means someone with only basic role-assignment permissions can give themselves or others the admin role, effectively taking over the entire database. The issue exists in versions before 1.38.0.