CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query. | |
| Title | CloudBeaver through 25.3.5 Missing Authorization via /api/sql-result-value Servlet | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:47.387Z
Reserved: 2026-10-11T01:53:20.486Z
Link: CVE-2026-108745
No data.
Status : Received
Published: 2026-10-11T13:17:19.097
Modified: 2026-10-11T13:17:19.097
Link: CVE-2026-108745
No data.
OpenCVE Enrichment
Updated: 2026-10-11T13:45:03Z
Weaknesses