CVE-2026-25628
EUVD-2026-556706.02.2026, 21:16
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qdrant | qdrant | 1.9.3 ≤ 𝑥 ≤ 1.16.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration