Article
Cyber News / Article / Vulnerability in Aix-DB software

CE
CERT Polska-2026-06-10
Vulnerability in Aix-DB software
CERT Polska has received a report about vulnerability in Aix-DB software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-8335: A missing authentication check on the AixâDB/llm/process_llm_outendpoint allows unauthenticated clients to execute arbitrarySELECTSQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints.
All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.
We thank Eryk Winiarz for the responsible vulnerability report.
Related articles
Ab
AbinayaMapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
2 days ago
An
Anne Aarness - Chris PrallCrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
9 days ago
Sh
Shaked RotleviIntroducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat Era
10 days ago
