Article

    Cyber News / Article / Vulnerability in Aix-DB software

    Vulnerability in Aix-DB software
    CE
    CERT Polska-2026-06-10

    Vulnerability in Aix-DB software

    CERT Polska has received a report about vulnerability in Aix-DB software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-8335: A missing authentication check on the Aix‑DB/llm/process_llm_outendpoint allows unauthenticated clients to execute arbitrarySELECTSQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints.

    All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.

    We thank Eryk Winiarz for the responsible vulnerability report.

    Original source