PatchSiren

crate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH crate CVE published 2026-08-14

CVE-2026-49989

CVE-2026-49989 debrief: Authenticated users can access or manipulate blobs in CrateDB, regardless of grants, posing significant risks to data confidentiality and integrity. This issue arises from a lack of AccessControl checks in the blob HTTP API, allowing unauthorized blob operations. CrateDB administrators and users with blob access must verify and update configurations to restrict blob access and ensu [truncated]