PT-2026-67329 · Arcadedb · Arcadedb

·

CVE-2026-67356

·

Published

2026-08-02

·

Updated

2026-08-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.7.3
Description An issue exists where the LocalDatabase object is bound into JavaScript trigger contexts using HostAccess.ALL. This allows users with UPDATE SCHEMA permissions to bypass permission checks by calling the getSecurity().createUser() function. An attacker can exploit this by creating triggers that execute JavaScript to create server-wide administrator accounts, resulting in privilege escalation.
Recommendations Update ArcadeDB to version 26.7.3 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67356
GHSA-38PF-6HP2-PXWW

Affected Products

Arcadedb