PT-2026-67324 · Arcadedb · Arcadedb

CVE-2026-67344

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.7.2
Description An issue exists where the system fails to enforce the UPDATE SCHEMA database permission during ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations. These operations map to the setCustomValue() and setBucketSelectionStrategy() functions in LocalDocumentType. An authenticated user with read-only access can use the HTTP command endpoint to modify a type's custom schema metadata and bucket-selection strategy, bypassing permission boundaries and potentially corrupting schema metadata and record routing.
Recommendations Update to version 26.7.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67344
GHSA-8VR5-263F-X5R3

Affected Products

Arcadedb