CVE-2026-8335
Last modified
CVE-2026-8335 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.
Metrics
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Aix-DB | Aix-DB | <= 1.2.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-8335?
How severe is CVE-2026-8335?
How do I fix CVE-2026-8335?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8321A vulnerability was detected in inkeep agents 0.58.14. This …7.3
- CVE-2026-8325A maliciously crafted PDF file, when parsed through Autodesk…7.8
- CVE-2026-8326Path traversal vulnerability in Remote Spark (https://www.Re…10
- CVE-2026-8327Concrete CMS below 9.5.0 and below is vulnerable to password…4.3
- CVE-2026-8328The ftpcp() function in Lib/ftplib.py was not updated when …5.9
- CVE-2026-8330GitLab has remediated an issue in GitLab CE/EE affecting all…4.4
- CVE-2026-8336After invoking $_internalJsEmit, which is not intended to be…6.5
- CVE-2026-8337Concrete CMS 9.5.0 and below is vulnerable to IDOR in survey…5.3
- CVE-2026-8338A Spring Security authentication and authorization bypass ex…9.2
- CVE-2026-8339A SQL injection vulnerability exists in the Coverity Connect…8.7
- CVE-2026-8340Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backe…4.3
- CVE-2026-8342Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
Are you affected by CVE-2026-8335?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
