PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108742 DBeaver CVE debrief

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation. This allows view-only shared-project members to persist credentials without datasource-edit permission. The CVE record was published on 2026-10-11T12:19:46.154Z and has not been modified since then. Defenders should assess exposure and prioritize remediation, particularly for instances with shared projects and view-only members. The vulnerability lets attackers set saveCredentials and sharedCredentials flags with chosen authProperties, enabling connections under the attacker's database identity.

Vendor
DBeaver
Product
CloudBeaver
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for CloudBeaver instances, particularly those with shared projects and view-only members, should assess exposure and prioritize remediation to prevent unauthorized access and potential credential compromise. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

Defenders should prioritize verifying and remediating this vulnerability in CloudBeaver instances, particularly those with shared projects and view-only members, to prevent unauthorized access and potential credential compromise.

  • Verify and restrict access to the initConnection GraphQL mutation to prevent unauthorized credential persistence.
  • Monitor for suspicious activity related to shared project connections and database identities.
  • Update to a patched version of CloudBeaver if available.

Technical summary

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation. This allows view-only shared-project members to persist credentials without datasource-edit permission. The vulnerability lets attackers set saveCredentials and sharedCredentials flags with chosen authProperties, enabling connections under the attacker's database identity. Defenders should prioritize verifying and remediating this vulnerability in CloudBeaver instances, particularly those with shared projects and view-only members.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in CloudBeaver instances, particularly those with shared projects and view-only members.

Recommended defensive actions

  • Verify CloudBeaver instances for version 25.3.5 or earlier and update to a patched version if available.
  • Restrict access to the initConnection GraphQL mutation to prevent unauthorized credential persistence.
  • Monitor for suspicious activity related to shared project connections and database identities.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the missing authorization vulnerability in CloudBeaver's initConnection GraphQL mutation. However, the corpus does not provide explicit information on exploitation or impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108742 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108742

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108742 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108742

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108742.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind03/cloudbeaver-initconnection-shared-credential-authz-bypass

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/dbeaver/cloudbeaver/blob/48885c48f5fbd363bf3391f47a669629b4f3dd24/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/dbeaver/cloudbeaver/blob/48885c48f5fbd363bf3391f47a669629b4f3dd24/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/impl/WebServiceCore.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/dbeaver/cloudbeaver

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/cloudbeaver-through-25.3.5-missing-authorization-via-initconnection-graphql-mutation

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.