CVE-2026-103534

medium

Description

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.

References

https://vuldb.com/vuln/412346/cti

https://vuldb.com/vuln/412346

https://vuldb.com/submit/957818

https://vuldb.com/cve/CVE-2026-103534

https://github.com/David-Crty/databasement/security/advisories/GHSA-vx6q-v2gv-5fhv

https://github.com/David-Crty/databasement/releases/tag/v1.7.2

https://github.com/David-Crty/databasement/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90467

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-01

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium