CVE 7.1 HIGH

Missing authentication in Aix-DB_CVE-2026-8335

7.1 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints.
All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.

Basic Information

ID CVE-2026-8335
Source CERT-PL
Published Jun 10, 2026 at 14:31

Affected Product

Vendor Aix-DB
Product Aix-DB
Affected Versions Aix-DB Aix-DB 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.