PT-2026-67324 · Arcadedb · Arcadedb
CVE-2026-67344
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.7.2
Description
An issue exists where the system fails to enforce the
UPDATE SCHEMA database permission during ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations. These operations map to the setCustomValue() and setBucketSelectionStrategy() functions in LocalDocumentType. An authenticated user with read-only access can use the HTTP command endpoint to modify a type's custom schema metadata and bucket-selection strategy, bypassing permission boundaries and potentially corrupting schema metadata and record routing.Recommendations
Update to version 26.7.2 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb