Arcadedb · Arcadedb · CVE-2026-93594
**Name of the Vulnerable Software and Affected Versions**
ArcadeDB versions prior to 26.9.1
**Description**
Access-control rules for per-type and per-record permissions are only enforced in LocalBucket. Query-execution paths accessing record data via LSM (Log-Structured Merge-tree) index files or the TimeSeries engine bypass these permission checks. Consequently, an authenticated user without `readRecord` or `deleteRecord` permissions can use SQL statements to read indexed key values, record IDs, and MAX/MIN values, as well as read and count TimeSeries samples and determine the total record count. Additionally, users can delete index entries, which desynchronizes the index from the data and may bypass unique constraints. The necessary index and type names are discoverable because the `SELECT FROM schema:indexes` query is unfiltered. This issue impacts embedded and server deployments across all transports, including HTTP, Bolt, Postgres, and Gremlin, once a principal is bound.
**Recommendations**
Update to version 26.9.1.