Authorization Bypass in Tabularis Database Management Software
CVE-2026-108604

5.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108604?

An incorrect authorization vulnerability in the Tabularis database management software allows malicious actors to circumvent read-only restrictions. Specifically, through the MCP run_query safety gate, attackers can submit side-effecting SELECT statements—such as 'SELECT setval', 'nextval', or 'query_to_xml'—embedded with destructive commands like DELETE. This flaw could enable unauthorized data modifications without proper approval prompts, posing a significant risk to data integrity and security.

Affected Version(s)

tabularis 0 <= 0.27.0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.