PT-2026-53168 · Undefined · Undefined

Published

2026-06-28

·

Updated

2026-06-28

·

CVE-2026-13512

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state key of the file src/query/service/src/servers/http/v1/session/client session manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13512

Affected Products

Undefined