PT-2026-48453 · Aix Db · Aix-Db

Eryk Winiarz

·

Published

2026-06-10

·

Updated

2026-06-10

·

CVE-2026-8335

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
A missing authentication check on the Aix‑DB "/llm/process llm out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-8335

Affected Products

Aix-Db