CVE-2026-61742

9.3

Bytebase · DBHub

Bytebase DBHub versions prior to 0.22.5 are vulnerable to DNS rebinding attacks, allowing unauthenticated remote attackers to execute MCP tool calls via a victim's browser.

Executive summary

A critical vulnerability in Bytebase DBHub allows unauthenticated remote attackers to bypass origin validation and execute unauthorized database operations, posing a severe risk to data integrity and confidentiality.

Vulnerability

This vulnerability involves a failure in origin validation during HTTP transport mode, specifically susceptible to DNS rebinding. This flaw allows an unauthenticated attacker to bypass security checks and invoke MCP tools, granting unauthorized access to the underlying database.

Business impact

The exploitation of this vulnerability can lead to unauthorized read, enumeration, and modification of database contents. Given the CVSS score of 9.3, this represents a critical risk where attackers could exfiltrate sensitive data or disrupt business operations by tampering with database records.

Remediation

Immediate Action: Upgrade Bytebase DBHub to version 0.22.5 or later immediately to resolve the origin validation flaw.

Proactive Monitoring: Review web server and application access logs for unusual traffic patterns or unexpected requests originating from external hostnames.

Compensating Controls: If an immediate update is not feasible, ensure that the DBHub instance is not exposed to the public internet and restrict access to trusted networks or via a VPN.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability presents a high risk due to the potential for unauthenticated database manipulation. Organizations utilizing DBHub in HTTP transport mode must prioritize the deployment of version 0.22.5 to close this security gap. Failure to patch allows for potential large-scale data exposure if the service is reachable by an attacker-controlled browser.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources