Missing Authorization in CloudBeaver WebSQLResultServlet Affects User Data Access
CVE-2026-108745
2.3LOW
What is CVE-2026-108745?
The CloudBeaver application through version 25.3.5 contains a significant flaw in the WebSQLResultServlet, which lacks proper authorization checks. As a result, any authenticated web session can access and download LOB export files from shared folders belonging to other users. This vulnerability enables an attacker to potentially infer table and column names, allowing for enumeration of timestamps and unauthorized retrieval of sensitive data from connections that the attacker lacks permissions to query. This poses a serious risk to user data privacy and security.
Affected Version(s)
CloudBeaver 0 <= 25.3.5
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
