Missing Authorization in CloudBeaver WebSQLResultServlet Affects User Data Access
CVE-2026-108745

2.3LOW

Key Information:

Vendor

Dbeaver

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108745?

The CloudBeaver application through version 25.3.5 contains a significant flaw in the WebSQLResultServlet, which lacks proper authorization checks. As a result, any authenticated web session can access and download LOB export files from shared folders belonging to other users. This vulnerability enables an attacker to potentially infer table and column names, allowing for enumeration of timestamps and unauthorized retrieval of sensitive data from connections that the attacker lacks permissions to query. This poses a serious risk to user data privacy and security.

Affected Version(s)

CloudBeaver 0 <= 25.3.5

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.