Executive brief
A database system fails to allow file owners to unlock resource locks created by other users, causing files to become permanently inaccessible. An attacker with any database access can lock files belonging to legitimate users, disrupting business operations with no recovery method except direct database intervention.
Technical details
The vulnerability exists in the file locking mechanism where TYPE_TOKEN locks placed by one user cannot be revoked or removed by the file owner or administrators. The affected component lacks proper authorization checks to allow lock removal by file owners. This results in a denial-of-service condition where locked files remain inaccessible until database-level manual intervention occurs.
Affected products
- <UNKNOWN>
Timeline
- 2026-09-21: disclosed