PT-2026-78405 · Arcadedb · Arcadedb

·

CVE-2026-76223

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.8.1
Description Insufficient enforcement of the UPDATE SCHEMA permission check occurs when a DEFINE FUNCTION statement targets an existing function library. This allows a user with only database access to add or overwrite SQL or Cypher functions within an existing library and persist those changes, which enables the tampering of admin-defined function logic. JavaScript functions are not affected as they still trigger the UPDATE SECURITY check.
Recommendations Update to version 26.8.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76223
GHSA-RV64-62HR-WV2P

Affected Products

Arcadedb