A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints.
All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.
CVSS
No CVSS.
References
Configurations
No configuration.
History
10 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 15:16
Updated : 2026-06-10 20:19
NVD link : CVE-2026-8335
Mitre link : CVE-2026-8335
CVE.ORG link : CVE-2026-8335
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
