PT-2026-53168 · Undefined · Undefined
Published
2026-06-28
·
Updated
2026-06-28
·
CVE-2026-13512
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state key of the file src/query/service/src/servers/http/v1/session/client session manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined