Description
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit permission. Attackers can set saveCredentials and sharedCredentials flags with chosen authProperties so other users connect to the shared connection under the attacker's database identity.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Credential Persistence
Action: Apply Patch
AI Analysis

Impact

CloudBeaver versions up to 25.3.5 allow a missing authorization check in the initConnection GraphQL mutation. View‑only members of shared projects can provide saveCredentials and sharedCredentials flags along with chosen authProperties, causing the service to store and reuse credentials under the attacker’s database identity. This results in persistent unauthorized database access by users who otherwise lack edit permissions on the data source.

Affected Systems

The vulnerability affects the DBeaver CloudBeaver product, specifically all releases up to and including version 25.3.5.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity impact. Because the exploit requires only the ability to invoke the initConnection mutation, attackers might achieve persistent credential theft if a user is allowed to perform the mutation. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the GraphQL API exposed by the server, where an attacker can directly submit the vulnerable mutation.

Generated by OpenCVE AI on October 11, 2026 at 14:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CloudBeaver to a patched release that adds authorization checks to the initConnection mutation.
  • Revoke any credentials that have been persisted by view‑only shared‑project members and enforce that only users with datasource‑edit rights are permitted to set saveCredentials or sharedCredentials flags.
  • Restrict or disable the persistence of shared credentials for users who lack edit permissions, either by configuration or by disabling the shared‑connections feature until a patch is applied.

Generated by OpenCVE AI on October 11, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit permission. Attackers can set saveCredentials and sharedCredentials flags with chosen authProperties so other users connect to the shared connection under the attacker's database identity.
Title CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:46.154Z

Reserved: 2026-10-11T01:53:16.533Z

Link: CVE-2026-108742

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:18.810

Modified: 2026-10-11T13:17:18.810

Link: CVE-2026-108742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses