SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13068

MEDIUM · CVSS 4.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Authenticated users with cursor termination privileges on one database can improperly terminate active cursors on a different database, potentially disrupting query operations for other users. This vulnerability arises from an inadequate authorization check that fails to restrict privileges to the correct namespace. Database administrators and security teams should prioritize addressing this issue to prevent unauthorized disruptions in multi-database environments.

CVE
CVE-2026-13068
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%

Original NVD Description

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.

Related CVEs

Other vulnerabilities affecting the same vendor(s)