Impact
CloudBeaver up to version 25.3.5 has a WebSQLResultServlet that omits an authorization check. Any authenticated web session can request the /api/sql-result-value endpoint, providing table and column names and timestamps, and read large object export files belonging to other users. Because the servlet does not verify that the requester owns the requested data, attackers can enumerate and download victim LOB values, including data from database connections they normally cannot query, resulting in a confidentiality breach.
Affected Systems
DBeaver’s CloudBeaver component deployed at version 25.3.5 or earlier is affected. The vulnerability lies in the WebSQLResultServlet and the associated DataLOBReceiver handling LOB export files stored in a shared folder that the application serves to authenticated users.
Risk and Exploitability
With a CVSS score of 2.3 the issue is classified as low severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. Exploitation requires only that an attacker possesses an authenticated web session; by sending the /api/sql-result-value request with guessed or enumerated table/column identifiers and second‑resolution timestamps, the attacker can retrieve protected LOB files. Attackers need no privileged database permissions, making the attack path relatively straightforward for someone who has obtained or compromised a session cookie.
OpenCVE Enrichment