A vulnerability identified as critical has been detected in crate CrateDB up to 6.2.7/6.3.1. Affected by this vulnerability is an unknown functionality of the component Blob HTTP API. This manipulation causes improper privilege management.

The identification of this vulnerability is CVE-2026-49989. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.