PT-2026-95372 · Arcadedb · Arcadedb

CVE-2026-93593

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ArcadeDB versions prior to 26.9.1
Description An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules. This occurs because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. The absence of a type-name-based access check causes permission lookups to fail open, allowing unauthorized access to TimeSeries data.
Recommendations Update to version 26.9.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93593
GHSA-WJHV-79GV-2PQG

Affected Products

Arcadedb