CVE-2026-49989
CrateDB blob HTTP handler authorization bypass - any authenticated user reads, deletes or plants blobs by SHA-1 digest
- Severity
- high
- Affected product
- CrateDB
- Affected versions
- CrateDB < 6.2.8
- Affected versions
- CrateDB ≥ 6.3.0, < 6.3.2
- Fixed in
- CrateDB 6.2.8
- Fixed in
- CrateDB 6.3.2
- Added to NewScan
- 2026-08-15
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints CrateDB from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-23 with the CrateDB fingerprint (tech_signatures body row on GET /, ok:true as the ES discriminator). Advisory: 'all releases before 6.2.8 and 6.3.2' - TWO branch rows per the never-widen rule rather than one lt over both fixes, because a single range would flag a patched 6.2.8+ build that has not yet taken the 6.3.2 fix (it does not need it). This is the up-to-6.2.x arm. The boundary: 6.2.7 in, 6.2.8 out; the measured 6.4.2 build (crate:latest, 2026-08-15 and 2026-08-23) fires the fingerprint and correctly NOT this row - that is the patched-arm negative case standing in until a 6.2.7 image is pulled. 'Any authenticated user' is near-vacuous on a default install: CrateDB ships with host-based auth OFF, so the interfaces /_sql row's posture finding and this advisory arm are the two halves of the same exposure.
COMPONENT VERSION RANGE
NewScan fingerprints CrateDB from its response and reports this CVE when the detected version falls inside the affected range below.
The 6.3-branch arm of CVE-2026-49989 (see the 6.2.x row for the full rationale): affected 6.3.0-6.3.1, fixed 6.3.2. Kept as a separate row so a 6.2.8/6.2.9 install - patched on its own branch - is never flagged by the 6.3 bound.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →