What is CVE-2026-49989?
In CrateDB before versions 6.2.8 and 6.3.2, any authenticated user can read, delete, or unconditionally write blobs if they know the SHA-1 digest, bypassing GRANT restrictions. Users are advised to update immediately.
Azərbaycanca: CrateDB-də autentifikasiya olunmuş istənilən istifadəçi, yalnız SHA-1 hash-ni bilməklə, blob-ları oxuya, silə və ya onlara dəyişiklik edə bilər. Bu zəiflik 6.2.8 və 6.3.2 versiyalarına qədər təsir edir, istifadəçilərə dərhal yeniləmə aparmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What information does an attacker need to exploit CVE-2026-49989?
Any authenticated user can read, delete, or unconditionally write blobs if they know the SHA-1 digest.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.