Authorization Bypass in Tabularis Database Management Software
CVE-2026-108604
5.8MEDIUM
What is CVE-2026-108604?
An incorrect authorization vulnerability in the Tabularis database management software allows malicious actors to circumvent read-only restrictions. Specifically, through the MCP run_query safety gate, attackers can submit side-effecting SELECT statements—such as 'SELECT setval', 'nextval', or 'query_to_xml'—embedded with destructive commands like DELETE. This flaw could enable unauthorized data modifications without proper approval prompts, posing a significant risk to data integrity and security.
Affected Version(s)
tabularis 0 <= 0.27.0
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
