Improper Authorization Affecting weaviate-fips-1.29 package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.28% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-WEAVIATEFIPS129-18470874
  • published31 Jul 2026
  • disclosed8 Jun 2026

Introduced: 8 Jun 2026

CVE-2026-11500  (opens in a new tab)
CWE-285  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest weaviate-fips-1.29.

NVD Description

Note: Versions mentioned in the description apply only to the upstream weaviate-fips-1.29 package and not the weaviate-fips-1.29 package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading to version 1.38.0-rc.0 is able to resolve this issue. The identifier of the patch is 40f2cc32279f0f8a51016c3c6870a2c0c808e6c0. You should upgrade the affected component.

CVSS Base Scores

version 3.1