CVE-2026-103534
Deferred Deferred - Pending Action

Improper Access Control in David-Crty Databasement

Vulnerability report for CVE-2026-103534, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
david_crty databasement to 1.7.1 (inc)
david_crty databasement 1.7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103534 is an improper access control vulnerability in the databasement application affecting versions 1.2.0 to 1.7.1. It allows authenticated users, even low-privilege roles like Viewer, to access, list, download, restore, or delete backup snapshots belonging to other organizations due to missing multi-tenant isolation in the Snapshot model. The root cause is the absence of an OrganizationScope in the Snapshot model's booted() method, unlike other tenant-sensitive models.

Detection Guidance

To detect this vulnerability, check if your databasement instance is running a version between 1.2.0 and 1.7.1. Verify the version by running: docker inspect <container_name> | grep Version or checking the web UI. Inspect API responses for /api/v1/snapshots to see if unauthorized users can list snapshots from other organizations. Test access controls by attempting to access snapshots outside your organization's scope.

Impact Analysis

This vulnerability enables attackers to access sensitive data such as personally identifiable information, credentials, and business data across tenant boundaries. They can perform unauthorized actions like downloading, restoring, or deleting backups, leading to data breaches, data tampering, or backup destruction. Exploitation requires only a valid user account and can be automated via API endpoints.

Compliance Impact

This vulnerability violates compliance requirements for GDPR and HIPAA by failing to enforce proper tenant isolation. It can lead to unauthorized access to protected health information or personal data, resulting in compliance violations, legal penalties, and reputational damage. The exploit undermines SOC2 controls as well.

Mitigation Strategies

Upgrade to databasement version 1.7.2 or later immediately. This can be done via Docker with: docker pull david-crty/databasement:1.7.2 and restarting the container. After upgrading, verify that access controls are enforced by testing snapshot access across organizations. Ensure no unauthorized users have elevated privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103534. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart