Answer in brief
CVE-2026-108742 records a Medium severity (CVSS 5.3) vulnerability in CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation. The current sources do not mark it as known exploited. The current feed maps DBeaver/CloudBeaver (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps DBeaver/CloudBeaver (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| DBeaver/CloudBeavergeneric | >=0 <=25.3.5 | Not reported |
Published upstream
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 11, 2026
CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit permission. Attackers can set saveCredentials and sharedCredentials flags with chosen authProperties so other users connect to the shared connection under the attacker's database identity.
Quoted source text, attributed separately from HOL analysis.