Authentication Bypass Vulnerability in CrateDB by Crate.io
CVE-2026-49989

7.1HIGH

Key Information:

Vendor

Crate

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-49989?

CrateDB suffers from an authentication bypass vulnerability affecting blob storage access. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete blobs if they know the SHA-1 digest, and can manipulate any blob table unconditionally, circumventing access controls. This flaw allows unauthorized content exposure through the blob HTTP API, despite proper access control enforcement via SQL commands. Deployments that utilize blob tables are particularly at risk, making immediate updates to the latest versions essential for secure operations.

Affected Version(s)

crate < 6.2.8 < 6.2.8

crate >= 6.3.0, < 6.3.2 < 6.3.0, 6.3.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.