CVE-2026-59093 | Weaviate up to 1.37.x RoleToGroup /authz/users privileges assignment

SecurityVulns

A vulnerability described as very critical has been identified in Weaviate up to 1.37.x. Impacted is an unknown function of the file /authz/users of the component RoleToGroup Handler. The manipulation results in incorrect privilege assignment.

This vulnerability is identified as CVE-2026-59093. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More