Sceawere

Vulnerability Detail

CVE-2026-108742UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CloudBeaver Missing Authorization Credential Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
DBeaver
Product
CloudBeaver
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit permission. Attackers can set saveCredentials and sharedCredentials flags with chosen authProperties so other users connect to the shared connection under the attacker's database identity.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T13:17:18.810Z",
  "pubdate": "2026-10-11T13:17:18.810Z",
  "executiveSummary": "CloudBeaver versions through 25.3.5 are susceptible to a missing authorization vulnerability within the initConnection GraphQL mutation.\nThis flaw allows users with view-only access to shared projects to bypass intended permission restrictions, specifically concerning datasource-edit capabilities.\nBy manipulating the initConnection mutation, an attacker can persistently store arbitrary credentials and configure authentication properties for a shared connection.\nThe vulnerability effectively enables credential hijacking, where an attacker forces other users—including those with higher privileges—to authenticate to a database using the attacker-supplied identity.\nThe risk implication is significant, as it facilitates unauthorized access to backend data sources by masquerading as a different database user. Exploitation requires an attacker to be an authenticated member of a shared project with at least view-only access, but it does not require administrative privileges within the CloudBeaver instance. This vulnerability poses a severe threat to data confidentiality and integrity by subverting the application's authentication delegation mechanism.",
  "technicalDetails": "The vulnerability resides within the processing logic of the 'initConnection' GraphQL mutation in CloudBeaver versions up to and including 25.3.5. The root cause is an insufficient authorization check that fails to validate whether the requester possesses the necessary 'datasource-edit' permission before modifying connection-specific configuration parameters.\nIn a typical CloudBeaver deployment, shared projects allow users to collaborate on database connections. Under normal operation, users lacking the 'datasource-edit' role should be restricted from altering the authentication persistence settings of these connections. However, the 'initConnection' mutation incorrectly permits these users to supply sensitive parameters, specifically the 'saveCredentials' boolean flag and the 'sharedCredentials' configuration, alongside arbitrary 'authProperties'.\nThe exploitation workflow proceeds as follows: First, the attacker identifies a target shared database connection where they possess 'view-only' privileges. Second, the attacker constructs a crafted GraphQL request targeting the 'initConnection' mutation. Within the payload, the attacker sets the 'saveCredentials' flag to true and provides a malicious set of 'authProperties' (e.g., username, password, or token) that corresponds to a database identity controlled by the attacker or one intended for impersonation.\nBecause the server-side logic of 'initConnection' fails to enforce the 'datasource-edit' authorization requirement, the application persists these malicious credentials within the shared connection's configuration. Once committed, the server updates the connection state for all members of the shared project. Subsequent attempts by any user (including administrators) to utilize the affected shared connection result in the application utilizing the attacker's injected credentials.\nThe downstream impact is a successful impersonation attack. Any connection established through the compromised shared resource is performed under the context of the attacker's supplied identity, effectively bypassing the security controls intended to isolate database access per user role. The payload behavior is strictly configuration-based, leaving little trace in standard application logs beyond the standard GraphQL mutation calls. This allows the attacker to pivot from a low-privilege view-only status to gaining unauthorized data access at the database layer without triggering typical authentication failure alerts, as the application effectively 'trusts' the malformed, persisted credential store."
}
CVE-2026-108742: CloudBeaver Missing Authorization Credential Injection (MEDIUM Severity, CVSS: 4.3) | Sceawere