PT-2026-53168 · Undefined · Undefined

Publicado

2026-06-28

·

Atualizado

2026-06-28

·

CVE-2026-13512

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state key of the file src/query/service/src/servers/http/v1/session/client session manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

Correção

Improper Authorization

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-13512

Produtos afetados

Undefined