| CVE ID | CVE-2026-8335 |
| Publication date | 10 June 2026 |
| Vendor | Aix-DB |
| Product | Aix-DB |
| Vulnerable versions | All through 1.2.4 |
| Vulnerability type (CWE) | Missing Authentication for Critical Function (CWE-306) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Aix-DB software and participated in coordination of its disclosure.
The vulnerability CVE-2026-8335: A missing authentication check on the Aix‑DB /llm/process_llm_out endpoint allows unauthenticated clients to execute arbitrary SELECT SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints.
All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.
Credits
We thank Eryk Winiarz for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.