PT-2026-96818 · Unknown · Databasement

·

CVE-2026-95654

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Databasement versions prior to 1.7.14
Description An authorization bypass occurs because invitation tokens are validated only when the acceptance page loads. The system caches the authorization decision and fails to re-verify the token validity during the final acceptance process. An attacker possessing a leaked or forwarded invitation link can load the page while the invitation is still pending and then complete the acceptance after the legitimate user has already done so. This allows the attacker to overwrite the account password and gain authenticated access to managed database credentials and secrets.
Recommendations Update to version 1.7.14 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95654

Affected Products

Databasement