Vulnerability in soar project
Author: ankitdnCreated Mar 3, 2026Updated Mar 3, 2026
While working on soar project, I identified CVE-2026-27965 affecting the Vitess package. The vulnerability allows unauthorized access through manipulation of backup files when an attacker has read/write access to the backup storage location (such as an S3 bucket).
Source: XiaoMi/soar