PT-2026-95373 · Arcadedb · Arcadedb
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.9.1
Description
Access-control rules for per-type and per-record permissions are only enforced in LocalBucket. Query-execution paths accessing record data via LSM (Log-Structured Merge-tree) index files or the TimeSeries engine bypass these permission checks. Consequently, an authenticated user without
readRecord or deleteRecord permissions can use SQL statements to read indexed key values, record IDs, and MAX/MIN values, as well as read and count TimeSeries samples and determine the total record count. Additionally, users can delete index entries, which desynchronizes the index from the data and may bypass unique constraints. The necessary index and type names are discoverable because the SELECT FROM schema:indexes query is unfiltered. This issue impacts embedded and server deployments across all transports, including HTTP, Bolt, Postgres, and Gremlin, once a principal is bound.Recommendations
Update to version 26.9.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb