CVE-2026-103534

Source
https://cve.org/CVERecord?id=CVE-2026-103534
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103534.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103534
Aliases
  • GHSA-vx6q-v2gv-5fhv
Published
2026-10-01T03:30:12Z
Modified
2026-10-07T02:30:18Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control
Details

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-266",
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103534.json"
}
References

Affected packages

Git / github.com/david-crty/databasement

Affected ranges

Type
GIT
Repo
https://github.com/david-crty/databasement
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.7.0"
        },
        {
            "last_affected": "1.7.0"
        },
        {
            "introduced": "1.7.1"
        },
        {
            "last_affected": "1.7.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.7.0
1.7.1
v1.*
v1.7.0
v1.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103534.json"