Arcadedb · Arcadedb · CVE-2026-93595
**Name of the Vulnerable Software and Affected Versions**
ArcadeDB versions prior to 26.9.1
**Description**
An access control bypass exists in the `query database` tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to the `DatabaseContext`, which causes Access Control List (ACL) checks for specific types and buckets to be ignored. This allows authenticated users to retrieve sensitive data from restricted types or buckets by prompting the AI assistant, bypassing the restrictions enforced on normal query endpoints.
**Recommendations**
Update ArcadeDB to version 26.9.1 or later.