{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/databasement/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:databasement:databasement:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-95654"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Databasement (\u003c 1.7.14)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cloud","web-application"],"_cs_type":"advisory","_cs_vendors":["Databasement"],"content_html":"\u003cp\u003eDatabasement versions prior to 1.7.14 contain a critical vulnerability in the invitation token handling process. The application validates invitation tokens exclusively upon the initial loading of the invitation acceptance page, caching the authorization decision rather than verifying the token status at the time of final acceptance. This flaw allows an attacker who has acquired a leaked or intercepted invitation link to bypass authentication controls. By loading the acceptance page while the invitation is still in a pending state, an attacker can wait for the legitimate recipient to use the link and subsequently submit their own request. The application fails to re-validate the token, permitting the attacker to overwrite the associated account password. This results in full unauthorized access to the victim's account, including all managed database credentials, connection strings, and sensitive secrets stored within the platform.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a pending invitation link via network traffic interception, log access, or email compromise.\u003c/li\u003e\n\u003cli\u003eAttacker loads the invitation acceptance page URL for the target account.\u003c/li\u003e\n\u003cli\u003eThe application caches the authorization decision for the invitation token upon the initial page load.\u003c/li\u003e\n\u003cli\u003eThe legitimate user accesses the same invitation link and completes the account setup process.\u003c/li\u003e\n\u003cli\u003eThe attacker submits the final account acceptance request through the application interface.\u003c/li\u003e\n\u003cli\u003eThe application performs no secondary validation of the invitation token's current status and trusts the cached decision.\u003c/li\u003e\n\u003cli\u003eThe application overwrites the legitimate user's credentials with those provided by the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker gains authenticated session access to the platform and exfiltrates managed database secrets.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthorized party to gain full control over a victim's Databasement account. This leads to the exfiltration of managed database credentials, potential modification of database configurations, and long-term persistence within the organization's cloud environment. The severity is compounded by the exposure of sensitive secrets that grant further lateral access to backend infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Databasement to version 1.7.14 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit platform logs for multiple successful account registrations or password changes associated with the same invitation token ID.\u003c/li\u003e\n\u003cli\u003eReview access logs for anomalous IP addresses accessing invitation links that were intended for specific internal users.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-22T16:38:23Z","date_published":"2026-09-22T16:38:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-databasement-auth-bypass/","summary":"Databasement versions before 1.7.14 are vulnerable to an authentication bypass where invitation tokens are improperly validated and cached, allowing attackers to hijack accounts and gain access to managed database credentials.","title":"Databasement Authentication Bypass via Improper Invitation Token Validation","url":"https://feed.craftedsignal.io/briefs/2026-09-databasement-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Databasement","version":"https://jsonfeed.org/version/1.1"}