Description
databasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example, --result-file=/app/public/index.php can write to index.php. In other words, quoting prevents OS command injection in mariadb-dump, but the argument injection alone is sufficient for code execution indirectly. NOTE: the project's composer.json file does not indicate an independently published databasement Composer package.
Published: 2026-10-11
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

In databasement versions prior to 1.8.2, the backup feature executes command-line utilities such as mariadb-dump with a database name supplied by an authenticated user. The supplied name is passed directly to the command without proper validation; an attacker can embed a result-file option to write to an arbitrary path, for example --result-file=/app/public/index.php. This indirect command injection allows the user to create or overwrite files through the web application, which can lead to executing arbitrary code within the web server context. The weakness aligns with CWE-88, shell command injection, and results in a high-severity, remote code execution vulnerability.

Affected Systems

The affected vendor is David‑Crty, product Databasement. Version 1.8.1 and earlier are vulnerable; any release before 1.8.2 can be exploited if the backup functionality is accessed by an authenticated user.

Risk and Exploitability

The CVSS score of 8.8 indicates a high impact risk. While the EPSS score is not published, the vulnerability is not currently listed in the CISA KEV catalog. Attackers need valid credentials with backup privileges; once granted, they can utilize the RCE to modify application files or execute arbitrary commands, making the threat likely and potentially costly for compromised hosts.

Generated by OpenCVE AI on October 11, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade databasement to version 1.8.2 or later, or apply the latest security patches available in the repository branches that address the backup injection issue.
  • Validate and sanitize the database name and all command-line arguments used by backup scripts; avoid passing untrusted input directly to shell-executed commands, or replace shell calls with parameterized API functions.
  • Restrict backup feature access to the minimum necessary user accounts, monitoring for abnormal file creation or modification; consider disabling the result-file parameter if not needed.

Generated by OpenCVE AI on October 11, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Authenticated User Remote Code Execution via Backup Command Injection
First Time appeared David-crty
David-crty databasement
Vendors & Products David-crty
David-crty databasement

Sun, 11 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description databasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example, --result-file=/app/public/index.php can write to index.php. In other words, quoting prevents OS command injection in mariadb-dump, but the argument injection alone is sufficient for code execution indirectly. NOTE: the project's composer.json file does not indicate an independently published databasement Composer package.
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

David-crty Databasement
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-11T19:38:44.171Z

Reserved: 2026-10-11T19:38:43.241Z

Link: CVE-2026-108963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T20:16:32.853

Modified: 2026-10-11T20:16:34.063

Link: CVE-2026-108963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T21:30:18Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')