CVE-2026-44719
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedMathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list, tables.metadata.list, explorations.list, and forms.list accept a database_id without verifying that the requesting user was a collaborator on that database. An authenticated user on the same Mathesar installation could use these methods to view Mathesar-managed metadata for databases where they were not a collaborator. Depending on the database and features in use, exposed metadata could include collaborator mappings, table metadata, saved exploration metadata, and form metadata. For forms, the exposed metadata included form tokens. For public forms, possession of the token is equivalent to possession of the public form link, which allows submission to the form under the form’s configured PostgreSQL role. This vulnerability is fixed in 0.10.0.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceMathesar versions 0.2.0 through 0.10.0 contain an IDOR vulnerability where the collaborators.list, tables.metadata.list, explorations.list, and forms.list API endpoints accept a database_id parameter without verifying the requesting user has collaborator access to that database, allowing authenticated users to view sensitive metadata including collaborator mappings, table metadata, exploration metadata, and form tokens for databases they are not authorized to access.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- Authentication
- X
- User interaction
- None
- Scope
- X
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Mathesar versionLocate and determine the installed Mathesar version in your environment using your package manager, container labels, or installation documentationAffected if The installed version falls between 0.2.0 and 0.10.0 inclusive
-
Confirm API endpoints are exposedVerify whether the API endpoints collaborators.list, tables.metadata.list, explorations.list, and forms.list are accessible in your deploymentAffected if Any of these four endpoints are exposed and reachable
-
Check authentication is enabledDetermine if user authentication is configured and functional in your Mathesar instanceAffected if Users can authenticate to the system, as the vulnerability requires an authenticated user context
-
Test database_id parameter authorizationUsing an authenticated session, attempt to access one of the affected endpoints with a database_id for a database the user should not have access toAffected if The endpoint returns metadata for databases the authenticated user is not authorized to access
Your environment is affected if Mathesar version 0.2.0 through 0.10.0 is installed, the affected API endpoints are exposed, and users can access metadata for databases they are not authorized to view.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade to Mathesar 0.10.0 or later which implements proper authorization checks for all database metadata endpoints.
0.10.0
- Identify the currently installed Mathesar version using the deployment method (e.g., docker images, package manager, or configuration files)
- Stop the Mathesar service to prevent access during the upgrade
- Back up the Mathesar database and configuration files
- Upgrade Mathesar to version 0.10.0 using the appropriate method (e.g., docker pull mathesar/mathesar:0.10.0, pip install mathesar==0.10.0, or Helm upgrade for Kubernetes deployments)
- Verify the upgrade was successful by checking the version number
- Restart the Mathesar service
- Verify that the authorization checks now properly validate user collaboration status before returning metadata
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation3.0 h
- Implementation6.0 h
- Testing3.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,984.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-44719 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-44719 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data