← Terug naar overzicht

QAnything 2.0.0 contains a critical authentication bypass vulnerability affecting two API endpoints: /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc. These endpoints fail to enforce authentication, allowing unauthenticated attackers to access any uploaded file or document within the system. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks. The vulnerability lacks ownership verification, enabling cross-tenant knowledge base content disclosure. This means an attacker can access documents belonging to other users or organizations hosted on the same instance. The issue is tracked as CVE-2026-85671 and affects specifically version 2.0.0 of QAnything by Netease Youdao. The vulnerability poses a significant risk to confidentiality in multi-tenant deployments of the QAnything knowledge base platform.

Affected products

  • QAnything 2.0.0

Related CVE's

  • CVE-2026-85671

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Identity & Access
  • Web Technologies