PT-2026-76947 · Arcadedb · Arcadedb
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.8.1
Description
ArcadeDB fails to bind the authenticated principal via the
setCurrentUser() function on its batch and time-series HTTP handlers. This prevents the fine-grained per-type Access Control List (ACL) layer, specifically the LocalBucket.checkPermissionsOnFile() function, from executing on the worker thread. Consequently, in deployments utilizing per-type or per-group ACLs, a user with database access but limited permissions can read from and write to unauthorized types by sending requests to the batch and time-series endpoints. Deployments relying exclusively on database-level access control are not affected.Recommendations
Update to version 26.8.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb