PatchSiren

Aix-DB CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Aix-DB CVE published 2026-06-10

CVE-2026-8335

CVE-2026-8335 is a high-severity vulnerability in Aix-DB, a product from an unknown vendor. The vulnerability exists due to a missing authentication check on the /llm/process_llm_out endpoint, which allows unauthenticated clients to execute arbitrary SELECT SQL queries and retrieve database data. All releases up to 1.2.4 are considered vulnerable, and the status of next releases is unknown as the vulnerab [truncated]