Vulnerability Description
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob storage: SQL (`SELECT ... FROM blob.<table>` and friends) and the blob HTTP API (`GET|PUT|DELETE /_blobs/{table}/{digest}`). The SQL path goes through `AccessControl`, which is what enforces privilege grants; that's why `SELECT digest FROM blob.secret_blobs` fails for a user who has no grants on the table. The HTTP path authenticates the request but never asks `AccessControl` whether the authenticated user is allowed to touch the table. So a user with no grants gets `MissingPrivilegeException` from SQL and `200 OK` plus the blob bytes from `GET /_blobs/secret_blobs/<digest>`. Deployments that don't use `BLOB TABLE` are unaffected. Authentication itself still works; the bug is strictly that being authenticated as anyone is treated as sufficient for any blob op. Versions 6.2.8 and 6.3.2 fix the issue.
Related Weaknesses (CWE)
References
- https://github.com/crate/crate/security/advisories/GHSA-2xv8-gjwh-fv8p
- https://github.com/crate/crate/security/advisories/GHSA-2xv8-gjwh-fv8p
FAQ
What is CVE-2026-49989?
CVE-2026-49989 is a documented vulnerability. CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in a...
How severe is CVE-2026-49989?
CVSS scoring is not yet available for CVE-2026-49989. Check NVD for updates.
Is there a patch for CVE-2026-49989?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.