PT-2026-78405 · Arcadedb · Arcadedb
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.8.1
Description
Insufficient enforcement of the
UPDATE SCHEMA permission check occurs when a DEFINE FUNCTION statement targets an existing function library. This allows a user with only database access to add or overwrite SQL or Cypher functions within an existing library and persist those changes, which enables the tampering of admin-defined function logic. JavaScript functions are not affected as they still trigger the UPDATE SECURITY check.Recommendations
Update to version 26.8.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb