A vulnerability described as critical has been identified in Volcengine OpenViking up to 0.2.13. Affected by this issue is some unknown functionality of the file /bot/v1/chat. Such manipulation leads to missing authentication.

This vulnerability is traded as CVE-2026-34999. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.