Missing Authorization in CloudBeaver Allows Credential Persistence
CVE-2026-108742
5.3MEDIUM
What is CVE-2026-108742?
CloudBeaver versions up to 25.3.5 have a vulnerability that allows members of shared projects to bypass permission controls through the initConnection GraphQL mutation. This issue enables users with view-only access to persist credentials, while they should not have the necessary datasource-edit permissions. By manipulating the saveCredentials and sharedCredentials flags, an attacker could connect other users under their database identity, potentially exposing sensitive data.
Affected Version(s)
CloudBeaver 0 <= 25.3.5
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
