---
id: CVE-2026-103534
title: A vulnerability was determined in David-Crty databasement up to 1.7.1
summary: >-
  A vulnerability was determined in David-Crty databasement up to 1.7.1.
  Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the
  file /api/v1/snapshots of the component Snapshot Model. This manipulation
  causes improper a…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-284
vendor: David-Crty
product: databasement
affected:
  - databasement 1.7.0
  - databasement 1.7.1
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T04:18:04.753'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103534'
references:
  - url: 'https://github.com/David-Crty/databasement/'
    label: cna@vuldb.com
  - url: 'https://github.com/David-Crty/databasement/releases/tag/v1.7.2'
    label: cna@vuldb.com
  - url: >-
      https://github.com/David-Crty/databasement/security/advisories/GHSA-vx6q-v2gv-5fhv
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-103534'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/957818'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/412346'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/412346/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T03:36:04.806Z'
---

## Overview

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
