Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user has already accepted it to overwrite the account password and gain authenticated access to managed database credentials and secrets. | |
| Title | Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T15:48:52.843Z
Reserved: 2026-09-22T12:28:58.960Z
Link: CVE-2026-95654
No data.
Status : Received
Published: 2026-09-22T16:18:18.770
Modified: 2026-09-22T16:18:18.770
Link: CVE-2026-95654
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization