PT-2026-76947 · Arcadedb · Arcadedb

·

CVE-2026-75850

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description ArcadeDB fails to bind the authenticated principal via the setCurrentUser() function on its batch and time-series HTTP handlers. This prevents the fine-grained per-type Access Control List (ACL) layer, specifically the LocalBucket.checkPermissionsOnFile() function, from executing on the worker thread. Consequently, in deployments utilizing per-type or per-group ACLs, a user with database access but limited permissions can read from and write to unauthorized types by sending requests to the batch and time-series endpoints. Deployments relying exclusively on database-level access control are not affected.
Recommendations Update to version 26.8.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75850
GHSA-C23X-PQCJ-7HFM

Affected Products

Arcadedb