CVE-2026-103534 Details
Description
A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.
A vulnerability exists in David-Crty Databasement versions prior to 1.7.2, specifically within the Snapshot Model's access control functions. The issue allows authenticated users, even those with the lowest privileges, to improperly access and manipulate backup snapshots across all organizations in a multi-tenant environment. This vulnerability has been publicly disclosed and can be exploited remotely.
Users are advised to upgrade to David-Crty Databasement version 1.7.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/David-Crty/databasement/ | [email protected] | Vendor |
| https://github.com/David-Crty/databasement/releases/tag/v1.7.2 | [email protected] | Release NotesVendor |
| https://github.com/David-Crty/databasement/security/advisories/GHSA-vx6q-v2gv-5fhv | [email protected] | AdvisoryExploitRemedyVendor |
| https://vuldb.com/cve/CVE-2026-103534 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/957818 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/412346 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/412346/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| David-Crty databasement | >= 1.2.0, < 1.7.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 1, 2026 | New CVE Received | [email protected] |
Volerion