CVE-2025-11060

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.
Configurations

No configuration.

History

26 Sep 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-26 13:15

Updated : 2025-09-26 14:32


NVD link : CVE-2025-11060

Mitre link : CVE-2025-11060

CVE.ORG link : CVE-2025-11060


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization