A vulnerability has been found in Tencent WeKnora up to 0.3.6 and classified as critical . Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint . The manipulation of the argument kbId leads to authorization bypass. This vulnerability is traded as CVE-2026-8786 . It is possible to initiate the attack remotely. Furthermore, there is an exploit available. The vendor was contacted early about this