CVE-2026-44718
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedMathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete operate on an exploration_id without verifying that the requesting user was a collaborator on the exploration’s database. An authenticated user on the same Mathesar installation who knew or guessed an exploration ID could read, replace, or delete a saved exploration belonging to a database where they were not a collaborator. This affected Mathesar-managed saved exploration definitions, including names, descriptions, selected columns, display metadata, filters, sorting, and transformations. This vulnerability is fixed in 0.10.0.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceMathesar versions 0.2.0 to before 0.10.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the explorations.get, explorations.replace, and explorations.delete endpoints. These endpoints fail to verify that the requesting user has collaboration permissions on the exploration's associated database before allowing read, modify, or delete operations, allowing authenticated users to access explorations on databases where they are not collaborators.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- Authentication
- X
- User interaction
- None
- Scope
- X
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Mathesar installation versionLocate the installed Mathesar version by checking the package.json, requirements.txt, or the application's about/settings page. Common locations: /mathesar/package.json or the Docker image tag.Affected if The installed version is 0.2.0 or higher but lower than 0.10.0
-
Confirm explorations feature is activeVerify that the Mathesar installation has explorations enabled. Check if users have created or can access explorations through the API endpoints at /api/v0/explorations/ or through the web interface.Affected if Explorations functionality is in use and the version falls within the affected range
-
Review database collaboration settingsExamine the database collaboration permissions configuration in Mathesar. Check which users are assigned as collaborators on databases that have explorations. This can be done via Mathesar's admin interface or API by querying the collaborations endpoint.Affected if There are databases with explorations where users exist who are NOT listed as collaborators on those databases but may have API access
A user is affected if Mathesar version is 0.2.0 through 0.9.x and explorations are being used, regardless of collaboration configuration, since the vulnerability allows unauthorized access to any exploration regardless of permissions.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade Mathesar to version 0.10.0 or later, which implements proper database collaboration verification before allowing exploration operations.
0.10.0
- Verify current Mathesar installation version using the system's package manager or deployment method
- Consult the Mathesar 0.10.0 release notes for any migration requirements or breaking changes
- Back up the current Mathesar database and configuration files
- Upgrade Mathesar to version 0.10.0 or later using the appropriate method (e.g., pip install mathesar==0.10.0, Docker image tag, or package manager)
- Verify the upgrade completed successfully and test that the application functions correctly
- Confirm that explorations.get, explorations.replace, and explorations.delete endpoints now properly validate user collaboration before allowing access
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation3.0 h
- Implementation6.0 h
- Testing4.0 h
- Review / QA3.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $4,512.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-44718 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-44718 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data