Authorization Bypass in Databend's Tenant Handler Component
CVE-2026-13512
Key Information:
Badges
What is CVE-2026-13512?
A security flaw has been discovered in the Tenant Handler component of Databend, specifically within the ClientSessionManager::state_key function. This vulnerability enables unauthorized access by manipulating session states, effectively bypassing authorization checks. The issue is present in Databend versions up to 1.2.881 and can be exploited remotely, raising significant security concerns. A public exploit is available, and a pull request aimed at addressing this vulnerability is currently awaiting approval.
Affected Version(s)
Databend 1.2.881
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
