Authentication Bypass Vulnerability in CrateDB by Crate.io
CVE-2026-49989
7.1HIGH
What is CVE-2026-49989?
CrateDB suffers from an authentication bypass vulnerability affecting blob storage access. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete blobs if they know the SHA-1 digest, and can manipulate any blob table unconditionally, circumventing access controls. This flaw allows unauthorized content exposure through the blob HTTP API, despite proper access control enforcement via SQL commands. Deployments that utilize blob tables are particularly at risk, making immediate updates to the latest versions essential for secure operations.
Affected Version(s)
crate < 6.2.8 < 6.2.8
crate >= 6.3.0, < 6.3.2 < 6.3.0, 6.3.2
