Impact
CloudBeaver versions up to 25.3.5 allow a missing authorization check in the initConnection GraphQL mutation. View‑only members of shared projects can provide saveCredentials and sharedCredentials flags along with chosen authProperties, causing the service to store and reuse credentials under the attacker’s database identity. This results in persistent unauthorized database access by users who otherwise lack edit permissions on the data source.
Affected Systems
The vulnerability affects the DBeaver CloudBeaver product, specifically all releases up to and including version 25.3.5.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity impact. Because the exploit requires only the ability to invoke the initConnection mutation, attackers might achieve persistent credential theft if a user is allowed to perform the mutation. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the GraphQL API exposed by the server, where an attacker can directly submit the vulnerable mutation.
OpenCVE Enrichment