Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance. | |
| Title | zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control | |
| First Time appeared |
Zilliztech
Zilliztech deep-searcher |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:zilliztech:deep-searcher:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zilliztech
Zilliztech deep-searcher |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-08T13:44:25.703Z
Reserved: 2026-06-07T09:20:16.327Z
Link: CVE-2026-11466
Updated: 2026-06-08T13:44:19.502Z
Status : Deferred
Published: 2026-06-07T23:16:42.213
Modified: 2026-06-08T14:57:14.757
Link: CVE-2026-11466
No data.
OpenCVE Enrichment
Updated: 2026-06-09T09:00:51Z