Skip to content
WeaviateGHSA-jqpm-wf57-qx5c

Weaviate has an Improper Authorization issue

Low5.0CVE-2026-11500 · Published Jun 8, 2026 · updated Aug 18, 2026

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading to version 1.38.0-rc.0 is able to resolve this issue. The identifier of the patch is 40f2cc32279f0f8a51016c3c6870a2c0c808e6c0. You should upgrade the affected component.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/weaviate/weaviate
Go
< 1.38.0-rc.01.38.0-rc.0
Details and references

More Weaviate advisories

All Weaviate
Advisory
Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
HighDec 12, 2025
Weaviate OSS has path traversal vulnerability via the Shard Movement API
HighDec 12, 2025
Weaviate denial of service vulnerability
High7.5Aug 22, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.