VYPR

cloudbeaver

by Weaver

CVEs (2)

  • CVE-2026-108742MedOct 11, 2026
    risk 0.28cvss 4.3epss —

    CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit permission. Attackers can set saveCredentials and sharedCredentials flags with…

  • CVE-2026-108745LowOct 11, 2026
    risk 0.20cvss 3.1epss —

    CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps…