Sceawere
Vulnerability Detail
CVE-2026-108745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CloudBeaver Missing Authorization LOB Access
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 4h ago
- Vendor
- DBeaver
- Product
- CloudBeaver
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-10-11T13:17:19.097Z",
"pubdate": "2026-10-11T13:17:19.097Z",
"executiveSummary": "CloudBeaver versions through 25.3.5 are affected by a missing authorization vulnerability located within the WebSQLResultServlet component.\nThis flaw permits an authenticated user with a valid web session to bypass access control mechanisms and retrieve Large Object (LOB) export files generated by other users stored in a shared directory.\nThe vulnerability represents a significant security risk, as it enables unauthorized data exfiltration, potentially exposing sensitive information from database connections that the attacker is not authorized to query.\nExploitation requires the attacker to possess an active session on the platform and successfully guess specific file naming conventions, which include database table names, column identifiers, and second-resolution timestamps.\nSuccessful exploitation leads to a complete breach of confidentiality regarding stored LOB data. The vulnerability highlights a failure in the application's authorization logic, which fails to restrict file access to the original owner or authorized session context, effectively allowing for cross-user file system traversal within the export directory.",
"technicalDetails": "The vulnerability resides in the WebSQLResultServlet of CloudBeaver, which is responsible for handling the retrieval and export of database query results, specifically LOB data. The root cause is a missing authorization check when the servlet processes requests for exported files stored on the server's backend storage.\nThe application stores exported LOB files in a shared, predictable directory structure. When a user requests an export, the system generates a file name that follows a deterministic pattern, incorporating the table name, the column name, and a timestamp accurate to the second. Because the WebSQLResultServlet lacks a robust authorization verification mechanism, it does not validate whether the user initiating the request owns the requested file or possesses legitimate access rights to the underlying database connection from which the file originated.\nThe attack flow follows a systematic enumeration process. An attacker with a valid, low-privileged session performs the following steps: 1. Identify the target environment, potentially by observing the application's behavior or via legitimate access to other data. 2. Derive potential table and column names associated with the target's LOB data. 3. Utilize the predictable second-resolution timestamp structure to construct potential file paths for exported LOBs. 4. Send crafted HTTP GET requests to the WebSQLResultServlet, systematically testing permutations of these identifiers and timestamps.\nBecause the servlet fails to restrict access, it responds to these requests by serving the LOB data associated with the guessed path directly to the attacker. This allows an attacker to bypass logical segmentation between different database connections and users. The impact is significant: an attacker can exfiltrate arbitrary files exported by any user on the system, potentially including highly sensitive binary data or large text objects that contain credentials, personally identifiable information, or proprietary business intelligence. The vulnerability effectively turns a shared storage repository into an insecure data lake, where the lack of session-based file isolation allows for unauthorized cross-tenant or cross-user data access. The requirement for a valid session indicates that this is not an unauthenticated exploit, but rather an authorization bypass that elevates the privileges of any registered user to access the full scope of the export directory."
}