AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:47.387Z and has not been modified since then. CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumer [truncated]
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation. This allows view-only shared-project members to persist credentials without datasource-edit permission. The CVE record was published on 2026-10-11T12:19:46.154Z and has not been modified since then. Defenders should assess exposure and prioritize remediation, particularly for instances with sh [truncated]