PatchSiren cyber security CVE debrief
CVE-2026-108742 DBeaver CVE debrief
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation. This allows view-only shared-project members to persist credentials without datasource-edit permission. The CVE record was published on 2026-10-11T12:19:46.154Z and has not been modified since then. Defenders should assess exposure and prioritize remediation, particularly for instances with shared projects and view-only members. The vulnerability lets attackers set saveCredentials and sharedCredentials flags with chosen authProperties, enabling connections under the attacker's database identity.
- Vendor
- DBeaver
- Product
- CloudBeaver
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for CloudBeaver instances, particularly those with shared projects and view-only members, should assess exposure and prioritize remediation to prevent unauthorized access and potential credential compromise. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Why it matters
Defenders should prioritize verifying and remediating this vulnerability in CloudBeaver instances, particularly those with shared projects and view-only members, to prevent unauthorized access and potential credential compromise.
- Verify and restrict access to the initConnection GraphQL mutation to prevent unauthorized credential persistence.
- Monitor for suspicious activity related to shared project connections and database identities.
- Update to a patched version of CloudBeaver if available.
Technical summary
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation. This allows view-only shared-project members to persist credentials without datasource-edit permission. The vulnerability lets attackers set saveCredentials and sharedCredentials flags with chosen authProperties, enabling connections under the attacker's database identity. Defenders should prioritize verifying and remediating this vulnerability in CloudBeaver instances, particularly those with shared projects and view-only members.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in CloudBeaver instances, particularly those with shared projects and view-only members.
Recommended defensive actions
- Verify CloudBeaver instances for version 25.3.5 or earlier and update to a patched version if available.
- Restrict access to the initConnection GraphQL mutation to prevent unauthorized credential persistence.
- Monitor for suspicious activity related to shared project connections and database identities.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the missing authorization vulnerability in CloudBeaver's initConnection GraphQL mutation. However, the corpus does not provide explicit information on exploitation or impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108742 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108742
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108742 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108742
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108742.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind03/cloudbeaver-initconnection-shared-credential-authz-bypass
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/dbeaver/cloudbeaver/blob/48885c48f5fbd363bf3391f47a669629b4f3dd24/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/DBWServiceCore.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/dbeaver/cloudbeaver/blob/48885c48f5fbd363bf3391f47a669629b4f3dd24/server/bundles/io.cloudbeaver.server/src/io/cloudbeaver/service/core/impl/WebServiceCore.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/dbeaver/cloudbeaver
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/cloudbeaver-through-25.3.5-missing-authorization-via-initconnection-graphql-mutation
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.