CVE-2026-108745
Received Received - Intake

Missing Authorization in CloudBeaver Exposes LOB Export Files

Vulnerability report for CVE-2026-108745, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
DBeaver CloudBeaver 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CloudBeaver through version 25.3.5 has a missing authorization vulnerability in the WebSQLResultServlet component. This flaw allows any authenticated user to access and read LOB export files belonging to other users from a shared folder. Attackers can exploit this by guessing table and column names and enumerating timestamps to download sensitive data, even from connections they normally couldn't query.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized access to the WebSQLResultServlet endpoint. Check for suspicious GET requests to /api/sql-result-value with guessed table/column names and timestamps. Inspect shared folder exports for unexpected LOB file downloads by unauthorized users.

Impact Analysis

If you use CloudBeaver 25.3.5 or earlier in a shared environment, an attacker with access to your web session could potentially read sensitive data files you exported. This includes database contents you intended to keep private, even from connections you don't have direct access to query.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements and HIPAA's privacy rules. Organizations using affected CloudBeaver versions may face compliance violations if user data is exposed through this flaw.

Mitigation Strategies

Upgrade CloudBeaver to version 25.3.5 or later to address the missing authorization vulnerability in WebSQLResultServlet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108745. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart