CVE-2026-108963
Deferred Deferred - Pending Action

Remote Code Execution in Databasement

Vulnerability report for CVE-2026-108963, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: MITRE

Description

databasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example, --result-file=/app/public/index.php can write to index.php. In other words, quoting prevents OS command injection in mariadb-dump, but the argument injection alone is sufficient for code execution indirectly. NOTE: the project's composer.json file does not indicate an independently published databasement Composer package.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
David-Crty databasement 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108963 is a Remote Code Execution (RCE) vulnerability in the databasement package before version 1.8.2. It allows authenticated users to inject malicious commands via the database name field during backup operations. Attackers can manipulate the database name parameter to include options like --result-file=/app/public/index.php, which writes arbitrary files to the system. This occurs because the application constructs shell commands using user-controlled input without proper sanitization.

Detection Guidance

Check for unauthorized file writes in web directories by monitoring for suspicious --result-file or similar options in database dump commands. Inspect logs for commands like mariadb-dump with unusual arguments. Verify if databasement versions prior to 1.8.2 are installed.

Impact Analysis

This vulnerability can lead to full system compromise. Attackers can write malicious files to sensitive locations, such as /app/public/index.php, potentially gaining control over the application. They may also access sensitive credentials like application keys, SSH keys, or cloud secrets stored on the system. Additionally, attackers could tamper with backups or restore operations, leading to data corruption or loss.

Compliance Impact

This vulnerability can severely impact compliance with GDPR and HIPAA. It may result in unauthorized access to personal or health data, leading to data breaches. GDPR requires protecting personal data and reporting breaches within 72 hours, while HIPAA mandates safeguarding protected health information. A successful exploit could violate these regulations, resulting in legal penalties, fines, and reputational damage.

Mitigation Strategies

Upgrade databasement to version 1.8.2 or later. Review and restrict database backup configurations to prevent arbitrary file writes. Implement input validation for database names and dump flags. Monitor for unauthorized file changes in web directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108963. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart