PatchSiren cyber security CVE debrief
CVE-2026-108604 TabularisDB CVE debrief
CVE-2026-108604 is a medium-severity vulnerability in Tabularis through version 0.27.0, which allows unauthorized modification of data by bypassing the read-only mode through the MCP run_query safety gate. This issue arises from an incorrect authorization vulnerability that enables prompt-injected agents or untrusted MCP clients to submit side-effecting SELECT statements, potentially leading to data modification without proper approval prompts.
- Vendor
- TabularisDB
- Product
- tabularis
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for Tabularis deployments, security teams assessing exposure to untrusted MCP clients or agents, and administrators of systems using Tabularis should be aware of this vulnerability. They should verify versions, assess exposure, and implement compensating controls to prevent unauthorized data modifications.
Why it matters
CVE-2026-108604 is a medium-severity vulnerability allowing unauthorized data modification in Tabularis through version 0.27.0. Defenders should verify versions, assess exposure, and implement controls to prevent unauthorized changes. Monitoring for specific types of SELECT statements is crucial.
- Potential unauthorized data modifications due to bypassed read-only mode.
- Need for verification of Tabularis versions in use.
- Requirement for compensating controls to prevent unauthorized changes.
- Importance of monitoring for side-effecting SELECT statements.
Technical summary
The vulnerability in Tabularis through version 0.27.0 arises from an incorrect authorization issue in the MCP run_query safety gate. This allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements, such as setval, nextval, or PostgreSQL query_to_xml with embedded DELETE, potentially modifying data without approval prompts. Affected product deployments should be identified and verified for exposure, with compensating controls implemented to prevent unauthorized data modifications.
Defensive priority
Defenders should prioritize verifying the versions of Tabularis in use, assessing exposure to untrusted MCP clients or agents, and implementing compensating controls to prevent unauthorized data modifications.
Recommended defensive actions
- Verify Tabularis versions in use and assess exposure to untrusted MCP clients or agents.
- Implement compensating controls to prevent unauthorized data modifications.
- Monitor for and restrict side-effecting SELECT statements.
- Review and update security configurations for MCP run_query safety gate.
- Perform asset inventory of systems using Tabularis to identify potential exposure.
- Review change management and rollback procedures for Tabularis deployments.
- Track and monitor for potential unauthorized data modifications.
Evidence notes
The CVE record and source references indicate a medium-severity vulnerability in Tabularis through version 0.27.0. The vulnerability allows unauthorized data modification by bypassing read-only mode. However, details about the exact versions affected, exploitation, or specific impacts are limited in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108604 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108604
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108604 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108604
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/TabularisDB/tabularis
-
Source reference
Unverified legacy reference
URL: https://github.com/TabularisDB/tabularis/blob/804c4c3bb6fd8eaa2e36cbe49f6c0d58f373b5e9/src-tauri/src/ai_activity.rs
-
Source reference
Unverified legacy reference
URL: https://github.com/TabularisDB/tabularis/blob/804c4c3bb6fd8eaa2e36cbe49f6c0d58f373b5e9/src-tauri/src/mcp/mod.rs
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/S1BofaIsMx
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/tabularis-through-0.27.0-read-only-bypass-via-mcp-run-query-select-classification
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.