← Back to search

CVE-2026-71379

10 CRITICALpublic exploit available

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
This vulnerability allows unauthenticated attackers to export arbitrary database tables, posing a significant risk to data integrity and confidentiality.
Exploitability
Exploitation is relatively straightforward as it requires sending a crafted POST request, and no authentication is needed.
Blast radius
If exploited, this could lead to unauthorized access to sensitive data, potentially compromising the entire database.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the file export endpoint or restrict access to it to only authenticated users.
webdata-exposureauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-552

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.