What is CVE-2026-65959?
In Vitess versions 24.0.2 and earlier, the `/debug/vrlog` endpoint lacks `acl.CheckAccessHTTP` authorization, potentially allowing unauthorized access to sensitive debug information. Affected deployments should upgrade to the latest version or restrict network access to mitigate the risk of information disclosure.
Azərbaycanca: Vitess verilənlər bazası klasterləmə sistemində 24.0.2 və daha əvvəlki versiyalarda `/debug/vrlog` endpoint-i `acl.CheckAccessHTTP` yoxlaması olmadan işləyir, bu isə icazəsiz istifadəçilərə həssas debug məlumatlarına giriş imkanı verə bilər. Təsirə məruz qalan sistemlərdə bu endpoint vasitəsilə məlumat sızması riski var, ona görə də ən son versiyaya yeniləmə və ya şəbəkə səviyyəsində giriş məhdudiyyəti tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Vitess are affected by CVE-2026-65959?
Vitess versions 24.0.2 and earlier are affected by this vulnerability.
Which endpoint is unprotected in CVE-2026-65959?
The `/debug/vrlog` endpoint operates without `acl.CheckAccessHTTP` authorization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.