Description
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query.
Published: 2026-10-11
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Data via LOB Export Files
Action: Assess Impact
AI Analysis

Impact

CloudBeaver up to version 25.3.5 has a WebSQLResultServlet that omits an authorization check. Any authenticated web session can request the /api/sql-result-value endpoint, providing table and column names and timestamps, and read large object export files belonging to other users. Because the servlet does not verify that the requester owns the requested data, attackers can enumerate and download victim LOB values, including data from database connections they normally cannot query, resulting in a confidentiality breach.

Affected Systems

DBeaver’s CloudBeaver component deployed at version 25.3.5 or earlier is affected. The vulnerability lies in the WebSQLResultServlet and the associated DataLOBReceiver handling LOB export files stored in a shared folder that the application serves to authenticated users.

Risk and Exploitability

With a CVSS score of 2.3 the issue is classified as low severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. Exploitation requires only that an attacker possesses an authenticated web session; by sending the /api/sql-result-value request with guessed or enumerated table/column identifiers and second‑resolution timestamps, the attacker can retrieve protected LOB files. Attackers need no privileged database permissions, making the attack path relatively straightforward for someone who has obtained or compromised a session cookie.

Generated by OpenCVE AI on October 11, 2026 at 13:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CloudBeaver to a version newer than 25.3.5 or apply the source code fix that restores proper authorization checks in WebSQLResultServlet.
  • Configure a reverse‑proxy or firewall rule to restrict access to the /api/sql-result-value endpoint to trusted IP ranges during remediation.
  • Disable the DataLOBReceiver feature or remove the /api/sql-result-value mapping if LOB exports are not required, thereby eliminating the vulnerable entry point.

Generated by OpenCVE AI on October 11, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query.
Title CloudBeaver through 25.3.5 Missing Authorization via /api/sql-result-value Servlet
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:47.387Z

Reserved: 2026-10-11T01:53:20.486Z

Link: CVE-2026-108745

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:19.097

Modified: 2026-10-11T13:17:19.097

Link: CVE-2026-108745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses