CVE-2026-44718

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete operate on an exploration_id without verifying that the requesting user was a collaborator on the exploration’s database. An authenticated user on the same Mathesar installation who knew or guessed an exploration ID could read, replace, or delete a saved exploration belonging to a database where they were not a collaborator. This affected Mathesar-managed saved exploration definitions, including names, descriptions, selected columns, display metadata, filters, sorting, and transformations. This vulnerability is fixed in 0.10.0.
CVSS

No CVSS.

Configurations

No configuration.

History

15 May 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 19:17

Updated : 2026-05-18 17:50


NVD link : CVE-2026-44718

Mitre link : CVE-2026-44718

CVE.ORG link : CVE-2026-44718


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-862

Missing Authorization