Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content. | |
| Title | QAnything 2.0.0 Unauthenticated Cross-User File Disclosure | |
| First Time appeared |
Youdao
Youdao qanything |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:youdao:qanything:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Youdao
Youdao qanything |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:26.116Z
Reserved: 2026-09-04T13:32:36.997Z
Link: CVE-2026-85671
No data.
Status : Received
Published: 2026-09-04T15:17:45.150
Modified: 2026-09-04T15:17:45.150
Link: CVE-2026-85671
No data.
OpenCVE Enrichment
Updated: 2026-09-04T16:00:05Z
-
CWE-306
Missing Authentication for Critical Function