HIGH
crate
CVE published 2026-08-14
CVE-2026-49989
CVE-2026-49989 debrief: Authenticated users can access or manipulate blobs in CrateDB, regardless of grants, posing significant risks to data confidentiality and integrity. This issue arises from a lack of AccessControl checks in the blob HTTP API, allowing unauthorized blob operations. CrateDB administrators and users with blob access must verify and update configurations to restrict blob access and ensu [truncated]