CVE-2026-59093 | Weaviate up to 1.37.x RoleToGroup /authz/users privileges assignment
A vulnerability described as very critical has been identified in Weaviate up to 1.37.x. Impacted is an unknown function of the file /authz/users of the component RoleToGroup Handler. The manipulation results in incorrect privilege assignment.
This vulnerability is identified as CVE-2026-59093. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More