๐Ÿ” CVE Alert

CVE-2026-108745

LOW 3.1

CloudBeaver through 25.3.5 Missing Authorization via /api/sql-result-value Servlet

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query.

CWE CWE-862
Vendor dbeaver
Product cloudbeaver
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for dbeaver cloudbeaver

Be the first to know when new low vulnerabilities affecting dbeaver cloudbeaver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

DBeaver / CloudBeaver
0 โ‰ค 25.3.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/cloudbeaver-sql-lob-servlet-missing-authorization github.com: https://github.com/dbeaver/cloudbeaver/blob/48885c48f5fbd363bf3391f47a669629b4f3dd24/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/sql/WebSQLResultServlet.java#L57-L94 github.com: https://github.com/dbeaver/cloudbeaver/blob/48885c48f5fbd363bf3391f47a669629b4f3dd24/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/sql/WebSQLDataLOBReceiver.java#L37-L70 github.com: https://github.com/dbeaver/cloudbeaver vulncheck.com: https://www.vulncheck.com/advisories/cloudbeaver-through-25.3.5-missing-authorization-via-api-sql-result-value-servlet

Credits

HaiND from the Post and Telecommunication Institute of Technology