CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-108742: CloudBeaver 0 through 25.3.5

Affected technology

CloudBeaver · 0 through 25.3.5
DBeaver

Description’s affected range: through 25.3.5

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Attackers can set saveCredentials and sharedCredentials flags with chosen authProperties so other users connect to the shared connection under the attacker's database identity. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low.

Published

CWE
CWE-862
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-108742.html